What happened
On Sep 23, 2026 attackers with access to MemTensor's GitHub release pipelines pushed malicious versions of two legitimate AI memory packages (an OpenClaw-agent MCP plugin and the MemoryOS Python library) carrying a Go credential-stealing implant. The attack alternated malicious and clean releases across a ~3.5 hour window, used no install hooks (so --ignore-scripts does not help), and included self-propagation capability for a supply-chain worm. No downstream spread confirmed yet; reported on Sep 23-25 and amplified through the window.
Why it matters
This is the first documented supply-chain worm targeting AI agent memory infrastructure. The compromised packages sit inside the agent's data path — the implant captures prompts at memory recall — and the host holds exactly the high-density credentials (registry, cloud, HH keys) agents need to function, making agent/memory-framework dependencies a prime pivot point. MemTensor plugins target OpenClaw, directly in both the prompt-injection and MCP supply-chain surface.
Attack vector
The malicious releases bundle a cross-platform Go implant ('sckit') launched through normal plugin/library code paths — the OpenClaw gateway startup and every memory-recall event (which passes the user's current prompt to the binary), and Python import/logging init. The implant harvests 13 classes of credentials (npm/PyPI tokens, GitHub/GitLab PATs, AWS keys, Hugging Face tokens, Vault, SSH keys, etc.) and exfiltrates to skyleen[.]fr; it also contains propagation hooks (recursivePublish/prepareRemote*) to push compromised versions of other packages.
Affected systems
npm @memtensor/memos-cloud-openclaw-plugin 0.1.21/0.1.23/0.1.25; PyPI MemoryOS 2.0.34 (MemTensor MemOS LLM/agent memory framework)
Mitigation
Pin npm to 0.1.20 and PyPI to 2.0.33 (or remove); rotate every credential reachable from affected hosts with registry tokens first; block skyleen[.]fr; audit lockfiles/SBOMs. Analysis: https://www.stepsecurity.io/blog/sckit-supply-chain-worm-hits-memtensor-npm-pypi-scopes and https://safedep.io/memtensor-sckit-worm-npm-pypi