Home / Companies / Socket / Blog / Post Details
Content Deep Dive

MemTensor npm and PyPI Packages Compromised in Credential-Stealing Supply Chain Attack

Blog post from Socket

Post Details
Company
Date Published
Author
Karlo Zanki
Word Count
1,853
Company Posts That Month
10
Language
English
Hacker News Points
-
Post removed?
No
Summary

MemTensor’s MemOS ecosystem was affected by a supply-chain attack in which malicious releases of the npm package @memtensor/memos-cloud-openclaw-plugin versions 0.1.21, 0.1.23, and 0.1.25, and PyPI package MemoryOS version 2.0.34, bundled cross-platform Go malware named sckit. The compromised npm plugin launches the payload when an OpenClaw gateway starts and during memory recalls, potentially exposing user prompts, while the PyPI package executes it when the memos module is imported. Static analysis indicates that the malware searches users’ home directories and environments for credentials including registry tokens, cloud keys, SSH keys, and API secrets, then communicates with command-and-control infrastructure under skyleen.fr; its capabilities may also support republishing packages using stolen tokens. Malicious code appeared in unauthorized-looking GitHub commits and altered release tooling, although the method used to obtain package publishing access remains unconfirmed. Organizations that installed the affected versions are advised to treat systems as compromised, remove or pin packages to known-good releases, rotate potentially exposed secrets, terminate sckit processes, investigate network traffic to the identified domain, and review recent package publishing activity for unauthorized releases.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
OpenClaw 19 11 3 2 -94%
Secrets Management 9 451 99 43 -80%
AI Agents 2 931 231 103 -84%
LLM 2 747 162 79 -85%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.