A Trusted Memory Layer Turns Hostile
MemOS is the kind of infrastructure project most enterprise engineering leaders have never heard of and increasingly depend on anyway. It gives AI agents a persistent memory layer, the piece of the stack that lets an agent remember context across sessions instead of starting cold every time it is invoked. With roughly 11,500 GitHub stars and 1,100 forks, it sits squarely in the growing category of open-source plumbing that agentic AI products quietly build on top of, the kind of dependency that shows up three or four layers deep in a vendor's stack rather than on any procurement checklist a buyer actually reviews.
That popularity is exactly what made it worth attacking. Researchers at Aikido, SafeDep, Socket, and StepSecurity independently flagged that three versions of MemTensor's MemOS Cloud OpenClaw plugin on npm, 0.1.21, 0.1.23, and 0.1.25, along with version 2.0.34 of the MemoryOS package on PyPI, had been compromised and were shipping a credential-stealing payload to anyone who installed them. Four independent security firms catching the same compromise within days of each other is itself a sign of how closely the npm and PyPI ecosystems are now being watched after a year of repeated supply-chain incidents, though it did nothing to stop the exposure window that came before detection.
How the Publish Pipeline Was Turned Against Itself
The attackers did not phish a maintainer's password or guess a weak credential. According to SafeDep's analysis, they obtained the project's npm and PyPI publish tokens directly from MemTensor's own GitHub Actions release pipeline, pushing commits engineered to trick the workflow into handing over the tokens it used to sign and ship releases. The account that pushed the malicious commits, tracked as leason1974, lacked the normal CI workflow signatures a legitimate maintainer commit would carry, a tell that pointed researchers straight to the compromise.
This is the pattern enterprise security teams should be tracking closely: the attack surface is no longer just the package itself, it is the automation that builds and publishes the package. A CI/CD pipeline with write access to a registry token is functionally equivalent to giving that pipeline the keys to every downstream install. Any organization running its own open-source release automation should read this as a direct hit on a pattern it likely uses too.
What the Malware Actually Does
The payload, a Go binary the researchers named sckit, is built to run on Windows, Linux, and macOS across both x64 and arm64 architectures, meaning it does not care what a developer's machine looks like. Once executed, it harvests credentials from an unusually wide net of platforms: npm, PyPI, GitHub, GitLab, AWS, HashiCorp Vault, Hugging Face, Slack, Stripe, SendGrid, and SSH keys, exfiltrating everything it finds to a command-and-control domain, skyleen[.]fr.
Socket's researchers found something more troubling buried in the binary than a straightforward credential grab. As they put it, "the binaries also contain strings about encoding package manifests and installing repository files. This suggests they may be able to republish packages with stolen registry tokens, indicating a potential worm behavior pattern." In plain terms, the malware appears built to use the credentials it steals to compromise the next package down the line, the same self-propagating mechanism that made prior npm worm campaigns spread so far so fast.
Why the Target List Should Worry CISOs
A credential stealer that targets Slack, Stripe, and SendGrid alongside AWS and GitHub is not built for a developer's laptop alone. It is built for the lateral movement that follows once a single compromised machine hands over the tokens that connect to payment processing, customer communications, and cloud infrastructure. A developer running a build with this package installed could unknowingly expose far more than their own repository access, handing an attacker a path into billing systems and customer-facing messaging tools that have nothing to do with the original open-source dependency they pulled.
The inclusion of Hugging Face and HashiCorp Vault in the target list is a signal worth sitting with on its own. Vault access implies the attacker is fishing for secrets management systems specifically, the place organizations concentrate their most sensitive credentials precisely because it is supposed to be the hardest target to reach. A stealer built to check for Vault tokens by default is a stealer built with enterprise environments, not hobbyist side projects, squarely in mind, and it argues for treating this less like a developer-laptop nuisance and more like a targeted enterprise credential-harvesting campaign that happened to arrive through an open-source dependency.
The Remediation Checklist
The fix for the immediate exposure is straightforward: pin to the last known clean versions, 0.1.20 on npm and 2.0.33 on PyPI, and block outbound traffic to skyleen[.]fr at the network edge. Any organization that ran the compromised versions, even briefly in a CI job or a local build that installed and discarded the dependency, should treat every credential accessible from that environment as burned and rotate it rather than assume the malware failed to find it in the short window it had.
Reviewing recent package publications tied to any accounts that touched the affected environment is the step teams most often skip under time pressure, and it is the one that catches whether the worm behavior Socket flagged actually executed. If an internal package was republished with a stolen token while nobody was watching, pinning the MemTensor version fixes nothing downstream, because the compromise has already moved one hop further into whatever registry that internal package feeds.
The Bigger Pattern in AI Infrastructure Supply Chains
This is not an isolated incident so much as the latest entry in a pattern that has hit npm and PyPI repeatedly through 2026: attackers targeting the open-source packages that AI agent tooling depends on, because that dependency graph has exploded in size faster than most security teams' review processes have adapted. MemOS sits in exactly the layer, agent memory and context management, that has seen the fastest package growth this year as teams race to ship agentic features.
For engineering leaders, the practical takeaway is that the AI infrastructure stack deserves the same software bill of materials discipline applied to any other production dependency, and arguably more, given how new and fast-moving this category is. Pinning versions, monitoring for anomalous publish activity on dependencies your build pulls automatically, and treating CI/CD publish tokens as crown-jewel secrets are no longer optional hygiene. They are the difference between a contained incident and a credential-farming worm loose inside your build pipeline.



