MemTensor Packages Steal Developer Secrets on Install
Socket.dev says MemTensor's npm package @memtensor/memos-cloud-openclaw-plugin and PyPI package MemoryOS are both compromised, and both registry copies are the latest versions. The packages target developers building from npm or PyPI, not end users.
The malicious code drops cross-platform Go binaries that search a developer's home directory for secrets and send them to skyleen[.]fr. That means the danger starts at install time: compromised local credentials can later be reused to reach source control, package publishing, cloud accounts, or other downstream artifacts.
For teams that trust dependency updates as a safety signal, this flips the usual check. The exposure sits on developer workstations and in CI environments with secrets on disk, so the package name alone no longer tells you whether the install is safe.