Originally published at RelayShield Blog.
On September 23, Aikido disclosed a Go-based worm it tracks as supplychain.local, published into the MemTensor packages on npm and PyPI after a threat actor seized their release access. The worm skips install-time hooks and fires on ordinary use, harvesting GitHub, npm, PyPI, AWS, Slack, and Stripe credentials from the environment. Then it weaponizes your own publish rights: direct npm and PyPI publishing with the stolen credentials, plus a GitHub Action template that re-triggers on every push.
Read that again. The worm doesn't attack your users. It turns you into the distributor.
The maintainer is the malware
This is the part that should keep you up at night. The MemTensor worm didn't exploit a vulnerability in the package code. It exploited the maintainer's laptop. Once it had their credentials, it published malicious versions as them, signed, trusted, and automatically pulled by every downstream user.
Your CI pipeline? It runs after push. By the time Snyk or GitHub Advanced Security flags the malicious package, the GitHub Action is already in your repo, re-triggering on every push, and the compromised version is already on npm.
The only checkpoint that runs before the damage leaves your machine is the pre-commit hook.
Count who can publish your dependencies
Here's the question nobody asks until it's too late: how many accounts can publish into your dependency tree?
When we built rsscan, we added rsscan --deps for exactly this reason. It counts the accounts with publish rights across your npm dependencies: the blast radius if any one of those maintainers gets compromised like MemTensor did.
rsscan --deps
If that number surprises you, that's the point.
The pre-commit hook is the point
rsscan blocks commits that introduce API keys, tokens, and machine credentials. It detects 31 credential patterns: AWS IAM keys, GitHub PATs, Stripe secrets, Slack tokens, private keys, LLM provider keys, and it runs entirely on your machine. No account, no API key, no network call. Your source code never leaves the host.
Why pre-commit and not CI? Because a CI check only sees the secret after a push. By then it's in git history and has to be rotated even if you delete the commit. The pre-commit hook runs before the commit enters history.
# .pre-commit-config.yaml
repos:
- repo: https://github.com/relayshield/rsscan
rev: v0.2.0
hooks:
- id: rsscan
pre-commit install
That's the whole setup. Nothing to configure, nothing to sign up for.
What MemTensor changes
The MemTensor worm proves three things:
- Your publish credentials are the target. Not your code, not your users: your ability to ship.
- Post-push detection is too late. The malicious GitHub Action executes on push. Scanning after the fact is forensics, not prevention.
- The supply chain is your laptop. Every credential on your machine is a potential distribution channel.
Run rsscan --deps. See how many people can publish into your dependencies. Then put the pre-commit hook in place so the next worm doesn't use your credentials to ship its malware.
rsscan is free and open source. Get it on GitHub. No account, no API key, no network calls. Your code never leaves your machine.
Top comments (0)