MemTensor AI Memory Tool Supply Chain Under Attack, Developer Credentials Face Leakage Risk
According to monitoring by blockchain security firm SlowMist (@SlowMist_Team), MemoryOS (PyPI), an AI memory toolkit under MemTensor, and its OpenClaw plugin (npm) were compromised in a supply chain attack. The affected versions ship with embedded cross-platform Go binaries that automatically execute malicious payloads when the package is loaded or imported.
Affected versions include MemoryOS==2.0.34 on PyPI, along with plugin versions 0.1.21, 0.1.23, and 0.1.25 on npm. Through this compromise, attackers can exfiltrate sensitive data such as npm/PyPI tokens, GitHub/GitLab credentials, AWS keys, SSH keys, API tokens, and environment variables. Exfiltrated data is sent back to the attacker-controlled infrastructure at skyleen[.]fr, and the compromised npm plugin may also leak user prompt inputs.
SlowMist advises users to immediately downgrade the affected packages to their secure versions (downgrade npm to 0.1.20 and PyPI to 2.0.33), terminate any sckit-related processes, block communication with the associated infrastructure, review network activity, and rotate all credentials across affected environments.