Vulnerabilities · 1 day ago
Socket.dev says MemTensor's npm package @memtensor/memos-cloud-openclaw-plugin and PyPI package MemoryOS are both compromised, and both registry copies are the latest versions. The packages target developers building from npm or PyPI, not end users.
The malicious code drops cross-platform Go binaries that search a developer's home directory for secrets and send them to skyleen[.]fr. That means the danger starts at install time: compromised local credentials can later be reused to reach source control, package publishing, cloud accounts, or other downstream artifacts.
For teams that trust dependency updates as a safety signal, this flips the usual check. The exposure sits on developer workstations and in CI environments with secrets on disk, so the package name alone no longer tells you whether the install is safe.
3 sources covering this story
Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI
Compromised MemTensor npm and PyPI packages deliver sckit, a Go-based stealer targeting cloud, registry, source-code, and developer credentials.
MemTensor npm and PyPI Packages Compromised in Credential-Stealing Supply Chain Attack
Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised.
AI Supply Chain Attack Hits an OpenClaw Memory Plugin
An AI supply chain attack backdoored MemTensor's MemOS packages on npm and PyPI, including its OpenClaw plugin.
Part of the PlainSec briefing for 2026-09-24