PANews|Sep 24, 2026 10:25
[SlowMist: MemoryOS and OpenClaw Plugin Compromised]
According to a security alert from SlowMist, the AI memory toolchain under MemTensor has been compromised. The open-source long-term memory library MemoryOS (PyPI), designed for LLMs and AI Agents, as well as the official plugin memtensor/memos-cloud-openclaw-plugin (npm) connecting to the OpenClaw runtime, have been injected with a cross-platform Go binary. This malicious program is triggered upon the package being loaded or imported.
Affected versions include: MemoryOS==2.0.34 on PyPI, and npm plugins 0.1.21, 0.1.23, and 0.1.25. Among these, the affected npm plugins may also lead to the leakage of user prompt content.
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink