Vulnerabilities & Exploits · Supply Chain

MemTensor Packages Steal Developer Secrets on Install

Socket.dev says MemTensor's npm package @memtensor/memos-cloud-openclaw-plugin and PyPI package MemoryOS are both compromised, and both registry copies are the latest versions. The packages target developers building from npm or PyPI, not end users.

The malicious code drops cross-platform Go binaries that search a developer's home directory for secrets and send them to skyleen[.]fr. That means the danger starts at install time: compromised local credentials can later be reused to reach source control, package publishing, cloud accounts, or other downstream artifacts.

For teams that trust dependency updates as a safety signal, this flips the usual check. The exposure sits on developer workstations and in CI environments with secrets on disk, so the package name alone no longer tells you whether the install is safe.

3 sources · Sep 23

Timeline

Sources

Part of the PlainSec briefing for 2026-09-23

Every edition of this story: MemTensor Packages Steal Developer Secrets on Install

More from today