In the early hours of 23 September 2026 UTC, an attacker published malicious releases of two packages from MemTensor, the team behind MemOS, an open-source memory framework for LLM agents with around 11,500 GitHub stars. The npm package @memtensor/memos-cloud-openclaw-plugin got three bad versions and the PyPI package MemoryOS got one. Each shipped a Go binary called sckit that searches your home directory for credentials and sends them to servers under skyleen[.]fr.
If you are building agents with MemOS, or with OpenClaw plugins, check your lockfiles now. If you are not, this is still worth five minutes, because it shows where supply-chain attackers are aiming next.
Which versions are bad
npm, @memtensor/memos-cloud-openclaw-plugin: 0.1.21, 0.1.23 and 0.1.25 are malicious. Socket's timeline shows 0.1.25 was tagged latest when it went up at 04:36 UTC. Clean releases 0.1.22 and 0.1.24 were published in between, which makes this messier than a single bad version. Socket's advice is to pin to 0.1.20, the last release before the attack (3 August); The Hacker News reports 0.1.24 as the latest clean version after the malicious ones were pulled.
PyPI, MemoryOS: 2.0.34 is malicious. The last safe version is 2.0.33. One easy tell: Socket notes the package grew from about 951 KB to about 19.2 MB, because it was carrying six platform binaries.
What the payload does
Both packages bundle sckit builds for Linux, macOS and Windows on x64 and arm64, and launch them detached in the background with your environment inherited. The npm version starts it when the OpenClaw gateway starts and again on every memory-recall operation โ and passes the user's prompt to it in an environment variable, SCKIT_EVENT_TEXT. The PyPI version fires on import via a logging configuration hook.
According to Socket, sckit looks for .npmrc files, Vault tokens, SSH keys, AWS access keys, GitHub and GitLab tokens, npm and PyPI tokens, Hugging Face, Slack, Stripe and SendGrid keys, JWTs, and any environment variable that looks like a secret. The Hacker News, citing researchers at Aikido, SafeDep, Socket and StepSecurity, adds that the implant can behave like a worm, with templates to plant itself in other npm and Python packages and in GitHub Actions workflows.
How it happened โ the sources disagree
This part is not settled. Socket says it could not confirm how the attacker got publishing access; it notes the npm releases were published by a maintainer account without a gitHead, pointing to direct registry access rather than CI. The Hacker News reports that the attacker obtained publish tokens from MemTensor's own GitHub Actions release pipelines by pushing commits that caused the workflow to hand them over. Both agree malicious commits appeared in MemTensor's repositories first. Until MemTensor publishes a post-mortem, treat the exact route as unconfirmed.
What to do if you installed a bad version
Assume the machine is compromised. That is Socket's position, and it is the right one for a credential stealer that ran in the background with your environment.
Rotate everything reachable from that user. npm and PyPI tokens, GitHub and GitLab tokens, cloud keys, SSH keys, Stripe and email-provider keys, and anything in .env files. Do it from a clean machine.
Kill and clean up. Stop any running sckit processes and delete ~/.openclaw/.cache/runtime/ and ~/.memos/.cache/runtime/.
Check the network. Block skyleen.fr and its subdomains, and review DNS, proxy and egress logs from 23 September onward.
Treat prompts as exposed. If the npm plugin ran, assume the prompts that passed through it were sent to the attacker. If your users put customer data into those prompts, that may be a data-protection question, not just a security one.
Check your own packages. Because of the worm behaviour, audit recent publishes and workflow changes on any registry account or repository the affected machine could reach.
Why agent tooling is a juicy target
A memory plugin for an agent is about as privileged as a dependency gets. It runs inside a process that holds API keys, sees every prompt, and often has tool access to the file system or the network. Much of this ecosystem is also young, fast-moving and maintained by small teams, so release pipelines are not always hardened. Pin exact versions of agent plugins, avoid pulling latest in CI, and run agent processes with only the secrets they actually need.
The bottom line
On 23 September, MemTensor's npm OpenClaw plugin (0.1.21, 0.1.23, 0.1.25) and PyPI MemoryOS (2.0.34) shipped a credential-stealing, self-spreading Go binary that also captured agent prompts. If any of those versions touched a machine you own, pin to a known-good release, rotate every secret that machine could see, and check your own packages. If not, take it as a prompt to pin and sandbox your agent dependencies before the next one.