Malicious versions of packages from MemTensor, the maintainer of the open-source MemOS memory framework for LLM agents (roughly 11,500 GitHub stars), were published to both npm and PyPI on September 23, 2026. They carry sckit, a cross-platform Go implant that harvests developer and CI credentials and includes templates to spread itself into other packages and workflows. SafeDep, StepSecurity and The Hacker News have all reported on it. It is the first documented worm aimed at AI agent memory infrastructure.
What Happened
Between roughly 02:23 and 05:55 UTC on September 23, an attacker pushed the following trojanized releases:
- npm:
@memtensor/memos-cloud-openclaw-plugin0.1.21, 0.1.23 and 0.1.25 (0.1.22 and 0.1.24 are reported clean) - PyPI:
MemoryOS2.0.34
The last known-good versions are 0.1.20 on npm and 2.0.33 on PyPI.
How the Attacker Got In
According to SafeDep, the attacker did not steal credentials from a maintainer’s laptop. They pushed commits that caused MemTensor’s own GitHub Actions release pipelines to hand over the npm and PyPI publish tokens. This is a pull_request_target-style misconfiguration, where a workflow with access to secrets executes attacker-influenced code. The npm releases were published under an account that had shipped legitimate releases before (leason1974), but they lack a gitHead field, so they did not come out of the project’s normal CI. That points to token or account abuse instead of a legitimate release.
Technical Details
The payload is a Go binary, sckit (also described as the “supplychain.local worm”), built for multiple operating systems and architectures:
- Triggers: in the Python package it runs on import. In the npm plugin it is wired into OpenClaw runtime hooks. It does not depend on an install script, so
--ignore-scriptsandpip installhygiene do not stop it. - Collection: 13 credential categories: npm and PyPI tokens, GitHub and GitLab personal access tokens, AWS access keys, Hugging Face tokens, HashiCorp Vault tokens, Slack tokens, Stripe live keys, SendGrid keys, SSH keys, generic JWTs, and any environment variable matching secret-shaped patterns.
- Exfiltration: captured data goes to infrastructure on
skyleen[.]frand its subdomains. - Propagation: the implant contains templates to inject itself into npm packages, Python packages and GitHub Actions workflows. Any publish token or repository write access it recovers can be used to compromise further projects, which is the same pattern as the Shai-Hulud family.
Impact
Anyone who installed or imported the listed versions in a developer workstation, CI runner, agent sandbox or container image should treat it as compromised. Agent frameworks are a bad place for this to land. They typically run with broad ambient credentials: cloud keys, model-provider tokens, and repository access. Because sckit publishes with stolen tokens, the blast radius extends to every package those tokens could publish, not just MemTensor’s.
Mitigation
- Pin to
@memtensor/memos-cloud-openclaw-plugin0.1.20 andMemoryOS2.0.33, or remove them. Purge caches, lockfile entries and built images that resolved the bad versions. - Rotate everything reachable from affected hosts: npm and PyPI tokens, GitHub/GitLab PATs, AWS keys, Hugging Face, Vault, Slack, Stripe and SendGrid credentials, SSH keys, and any secret in the environment. Rotate from a clean machine.
- Block
skyleen.frand all subdomains at DNS and egress, and search DNS and proxy logs from September 23 onward for lookups. - Audit publishing: review your own npm and PyPI publish history and GitHub Actions workflows for releases or workflow edits you did not make. Check for unexpected new workflow files, since that is one of sckit’s propagation paths.
- Harden CI: do not expose secrets to
pull_request_targetworkflows that check out or execute untrusted code, and move to trusted publishing (OIDC) with short-lived tokens scoped per workflow.