MemTensor MemOS supply chain: npm + PyPI releases drop sckit credential stealer (C2 skyleen[.]fr)
Socket (23 September 2026; corroborated by Aikido, SafeDep, StepSecurity; THN amplify same day) reports compromise of MemTensor MemOS packaging: npm @memtensor/memos-cloud-openclaw-plugin versions 0.1.21, 0.1.23, and 0.1.25 (0.1.25 tagged latest; 0.1.22/0.1.24 match last-good 0.1.20 aside from version strings; last known-good 0.1.20) and PyPI MemoryOS 2.0.34 (latest; last pre-compromise 2.0.33). Malicious builds bundle cross-platform Go implant sckit (linux/macOS/Windows x64+arm64) that launches on OpenClaw gateway start / memory-recall (npm) or on import memos (PyPI), harvests developer/CI secrets (npm/PyPI/GitHub/GitLab/AWS/Vault/SSH and related env tokens), and phones home to skyleen[.]fr. Initial access via malicious GitHub commits altering release tooling; Socket could not yet confirm how registry publish access was obtained. Treat any host that loaded the bad versions as compromised; worm-like republish strings noted but broader package impact unconfirmed. Primary: Socket analysis; secondary: The Hacker News 23 Sep 2026.
- Product
- MemTensor MemOS — npm @memtensor/memos-cloud-openclaw-plugin; PyPI MemoryOS
- Versions
- Malicious: npm 0.1.21 / 0.1.23 / 0.1.25; PyPI MemoryOS 2.0.34. Pin/remove to npm 0.1.20 and PyPI 2.0.33 (or uninstall) until maintainers publish verified clean latest.
- Exploited in Australia?
- unknown
- Patch to
- Pin npm to 0.1.20 and PyPI MemoryOS to 2.0.33 (or remove); treat hosts/CI that loaded bad versions as compromised — rotate npm/PyPI/GitHub/GitLab/AWS/Vault/SSH and related secrets; kill sckit; delete ~/.openclaw/.cache/runtime/ and ~/.memos/.cache/runtime/; block skyleen[.]fr and review egress since 23 Sep 2026; audit own package publishes if registry tokens were on affected hosts
Primary: Socket — MemTensor npm/PyPI compromise / sckit stealer (23 Sep 2026) · Vendor: Socket Research — MemTensor MemOS supply chain · The Hacker News — MemTensor sckit (23 Sep 2026)
