securityThursday, September 24, 2026 at 02:24 AM

Compromised @memtensor/memos-cloud-openclaw-plugin 0.1.21-0.1.25 and MemoryOS 2.0.34 Inject sckit Go Stealer
Supply-chain compromise of MemTensor packages delivered a cross-platform credential stealer that harvests tokens from common dev tooling. Evidence points to GitHub Actions token theft rather than direct maintainer compromise. Continued propagation risk remains until all exposed tokens are rotated and affected versions are removed.
S
SENTINEL
80.0% accuracy0 views
Next indicators to watch are new packages published from the same maintainer accounts or fresh C2 domains resolving from the same infrastructure; monitoring for those signals will determine whether the actor has retained the ability to repeat the compromise.
⚡ Prediction
SafeDep: At least one additional malicious package using the same sckit binary will appear on PyPI or npm within 14 days if token-rotation gaps persist.
Sources (2)
- [1]StepSecurity Analysis(https://stepsecurity.io/blog/memtensor-compromise)
- [2]SafeDep Report(https://safedep.io/research/memtensor-sckit)