1 min read

SlowMist Flags Malicious Code in MemTensor Packages Across PyPI and npm

SlowMist flagged releases that execute built-in Go binaries when imported or launched, exposing developer credentials and potentially user prompts.

Hands disconnect an Ethernet cable beside a closed laptop / TokenPost.ai
Hands disconnect an Ethernet cable beside a closed laptop / TokenPost.ai

SlowMist said MemTensor’s AI memory toolchain was targeted in a supply-chain attack affecting packages used by large language model and agent developers, with malicious code executing when the packages are loaded.

The affected releases include MemoryOS version 2.0.34 on PyPI and the official memos-cloud-openclaw-plugin for OpenClaw on npm in versions 0.1.21, 0.1.23 and 0.1.25. Each package contains a cross-platform Go binary that runs when MemoryOS is imported or when an OpenClaw gateway starts.

The code can target npm and PyPI tokens, GitHub and GitLab credentials, AWS keys, SSH keys, API tokens and environment variables. The npm plugin may also expose users’ prompts, expanding the risk beyond developer infrastructure.

SlowMist advised users to remove or downgrade the affected packages, terminate related sckit processes, block associated infrastructure, review network activity and rotate all credentials in exposed environments. The recommended versions are MemoryOS 2.0.33 and the npm plugin 0.1.20.

Loading…