MemTensor AI Memory Tool Supply Chain Attacked, Developer Credentials at Risk of Exposure

深潮TechFlow
深潮TechFlow|Sep 24, 2026 11:17
Deep Tide TechFlow reports that on September 24, according to monitoring by blockchain security company SlowMist (@SlowMist_Team), MemTensor's AI memory tool library MemoryOS (PyPI) and its OpenClaw plugin (npm) suffered a supply chain attack. The affected versions contain cross-platform Go binaries that automatically execute malicious code when the package is loaded or imported. The affected versions include MemoryOS==2.0.34 on PyPI, as well as plugin versions 0.1.21, 0.1.23, and 0.1.25 on npm. Through this attack, attackers can steal sensitive information such as npm/PyPI tokens, GitHub/GitLab credentials, AWS keys, SSH keys, API tokens, and environment variables. The data is transmitted back to attacker-controlled infrastructure at skyleen[.]fr. Additionally, the affected npm plugins may expose user prompt content. SlowMist recommends users immediately downgrade the relevant packages to secure versions (npm to 0.1.20, PyPI to 2.0.33), terminate related sckit processes, block the associated infrastructure, review network activity, and rotate all credentials in the affected environments.
+3
Mentioned
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads