# Supply-Chain Attack Hits Two MemTensor Tools, Developers Warned

By Simon Yoon

Canonical URL: https://www.tokenpost.com/news/technology/23662
Published: 2026-09-24T10:12:51.000Z
Updated: 2026-09-24T10:12:51.000Z

A supply-chain attack affected two MemTensor tools, and developers should check their installed versions for releases that execute malicious code when loaded.

The affected packages are the MemoryOS package on PyPI at version 2.0.34 and the OpenClaw plugin on npm at versions 0.1.21, 0.1.23 and 0.1.25. The malicious program is designed to run across multiple operating systems.

The exposure may put npm, PyPI, GitHub, Amazon Web Services, Secure Shell and API credentials at risk. Developers using any of the listed versions should move to a safe release, stop the affected process and rotate credentials that may have been exposed.

The incident underscores the risk of compromised dependencies in crypto software, where a package update or plugin load can introduce malicious activity into a developer’s environment.
