Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› MemTensor MemoryOS Supply Chain Attack 2026: How Stolen…
Breach analysis Incident: 23 Sep 2026

MemTensor MemoryOS Supply Chain Attack 2026: How Stolen CI Publish Tokens Put a Credential Stealer Inside AI Agent Memory

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 29 September 2026 10 min read
On this page

On 23 September 2026, an attacker published malicious versions of two MemTensor packages: the OpenClaw memory plugin @memtensor/memos-cloud-openclaw-plugin on npm, and the MemOS Python library MemoryOS on PyPI. Both carried the same Go implant, sckit. It runs in the background whenever the package loads, collects credentials from the developer's home directory and sends them to servers under skyleen[.]fr. The attacker did not steal the maintainers' passwords. They changed MemTensor's own GitHub Actions release pipelines so that the npm and PyPI publish tokens were captured as the workflows ran, then used the project's real release process to ship the backdoor. Because the npm plugin runs inside an AI agent's memory layer, the implant fired on every memory recall with the agent's full environment. The binary also contains code to spread itself using any publish tokens it finds.

Key takeaways

  • Malicious versions: npm @memtensor/memos-cloud-openclaw-plugin 0.1.21, 0.1.23 and 0.1.25, and PyPI MemoryOS 2.0.34, all published on 23 September 2026. A plain install pulled the backdoor, and --ignore-scripts did not help because the payload runs when the code loads.
  • SafeDep traced how the tokens were stolen. Commits pushed as the Memtensor-AI account made the release workflows load an attacker script through BASH_ENV, which handed the npm token and the PyPI API token to the implant before publishing.
  • The sckit implant targets npm and PyPI tokens, GitHub and GitLab tokens, SSH keys, AWS and other cloud CLI credentials, HashiCorp Vault tokens, Hugging Face credentials, JWTs and .env secrets under the home directory.
  • In the npm plugin, the implant starts when the OpenClaw gateway starts and again on every memory recall. It receives the full environment and the user's prompt text.
  • The binary includes code to copy itself into other repositories and packages that stolen credentials can reach. SafeDep had not seen further spread at the time of writing.

At a glance

OrganisationsMemTensor (maintainer of MemOS and the OpenClaw memory plugin); developers and AI agent deployments that installed the affected versions
WhenMalicious releases on 23 September 2026, between 02:23 and 05:25 UTC; reported by SafeDep and Socket the same day
AttackerUnknown. The npm versions came from the existing maintainer account leason1974; the GitHub changes were pushed as Memtensor-AI, probably with a stolen token (unconfirmed)
Entry pointCommits to MemTensor's GitHub repositories that hijacked GitHub Actions release workflows via BASH_ENV
Identities abusedThe Memtensor-AI GitHub account; the npm publish token and PyPI API token stored as GitHub Actions secrets; developer credentials harvested by the implant
ImpactBackdoored packages published to npm and PyPI; credential theft from every host that loaded them; worm capability to republish other packages
CategoryNHI, Agentic AI and AI agents. Incident class: confirmed NHI breach (CI publish tokens stolen and used; credential stealer shipped to users)

What happened

MemOS is an open-source memory framework for AI agents from MemTensor. Its main GitHub repository has about 11,500 stars, according to Socket. The OpenClaw plugin connects the OpenClaw agent gateway to MemOS's cloud memory. SafeDep's monitoring flagged a GitHub issue reporting that plugin versions 0.1.21 and 0.1.23 did not match any commit in the repository. SafeDep then reconstructed what happened from repository events, commit metadata and registry data.

Between 00:48 and 02:03 UTC on 23 September, the Memtensor-AI account created, pushed and deleted a release branch five times on the plugin repository. The commits changed a validation script so that it wrote a BASH_ENV entry into the GitHub Actions environment. Bash runs the file named in BASH_ENV before any non-interactive script, so the attacker's script ran just before the real npm publish step. It passed the npm token to the sckit binary, deleted itself, and failed the step so that nothing was published from that run. Twenty minutes later, npm version 0.1.21 appeared with the implant. On the MemOS repository, a commit added the sckit binaries and a custom Poetry build backend that used the same BASH_ENV trick to capture the PyPI API token. A second commit then let MemTensor's own workflow build the malicious package and upload it to PyPI with the project's real token. SafeDep found that the GitHub Actions API returned no workflow runs for the repositories after early September, and infers that the run logs were deleted. It could not confirm how the attacker got push access as Memtensor-AI, and says a stolen token is the most likely explanation.

Once installed, the implant starts without any install hook. In the npm plugin it launches when the OpenClaw gateway starts and again on every memory recall, detached, with the full environment and the user's prompt text. In MemoryOS it launches when the library configures logging, which almost every import path does. Socket reports that sckit searches the home directory for npm, PyPI, GitHub, GitLab and AWS credentials, HashiCorp Vault tokens, SSH keys, Hugging Face credentials and JSON Web Tokens, and sends them to skyleen[.]fr subdomains. SafeDep says the binary contains code to copy itself into other repositories and packages that stolen credentials can reach.

Timeline

Date (UTC)Event
23 September 2026, 00:48 to 02:03Memtensor-AI pushes and deletes a release branch five times on the OpenClaw plugin repository.
23 September 2026, 02:23npm 0.1.21 published with the sckit binary.
23 September 2026, 03:17Commit on MemTensor/MemOS adds sckit and a CI token stealer.
23 September 2026, 03:49npm 0.1.23 (malicious) published.
23 September 2026, 04:17A researcher opens an issue: published versions do not match any commit.
23 September 2026, 04:36npm 0.1.25 (malicious) published.
23 September 2026, 05:25MemoryOS 2.0.34 uploaded to PyPI with the implant.

How it happened: the identity attack path

  1. A trusted GitHub identity. The attacker pushed commits as Memtensor-AI, an account that had contributed to the project before. How they got its access is unconfirmed.
  2. Release workflows that trusted repository code. Scripts that ran earlier in the release job could change the environment of later steps, including the publish step.
  3. Publish tokens captured in the pipeline. Through BASH_ENV, the attacker's script ran inside the publish steps and took the npm token and PyPI API token as the workflows handed them over.
  4. The real release process, abused. For PyPI, the attacker let MemTensor's own workflow and token upload the malicious build, so the package looked like a normal release.
  5. An implant inside the agent runtime. The plugin ran in the OpenClaw gateway and fired on every memory recall, inheriting the agent's environment and credentials.
  6. Stolen tokens become the next foothold. The implant hunted for more publish tokens and included code to republish other packages, the pattern of recent package worms.

Impact

  • Packages: three malicious npm versions and one malicious PyPI version. At collection time, 0.1.25 held npm's "latest" tag and 2.0.34 was the newest PyPI release.
  • Credentials: any host that loaded an affected version should treat every credential in its home directory as exposed, including registry tokens, source control tokens, SSH keys, cloud credentials and Vault tokens.
  • Spread: worm capability present. SafeDep had not seen confirmed downstream spread, but warns the affected list can grow.
  • Attribution: unknown actor. Socket could not confirm how publishing access was obtained.

What this means for NHI and AI agent security

This attack is non-human identities from start to finish. It began with a machine-used GitHub account, ran through CI secrets, hijacked the publish tokens that registries trust, and ended with an implant harvesting the tokens and keys on developer and agent hosts. Our timeline shows the same shape in Shai-Hulud, ChainDrop and Miasma and Hades. Long-lived publish tokens stored as CI secrets remain one of the most valuable targets in the software supply chain.

What is new is where the implant sat. An agent memory component runs inside the agent's process on every recall, with the agent's environment. That environment often holds model provider keys, tool credentials and cloud access. Compromising a memory library is therefore a way into every credential the agent can use. Components inside agent runtimes need the same supply-chain scrutiny as anything else that runs with production secrets. Our AI Agent Memory Security Guide and AI Supply Chain and AI-BOM Guide cover this.

Recommendations

  • Remove and pin. Uninstall the affected versions and pin to npm 0.1.20 and PyPI 2.0.33, the last clean releases named by Socket. Kill any running sckit processes.
  • Rotate everything on affected hosts. Treat npm and PyPI tokens, GitHub and GitLab tokens, SSH keys, cloud credentials, Vault tokens and .env secrets as exposed. Use our Leaked Credential Response Playbook.
  • Replace publish tokens with trusted publishing. Use OIDC-based trusted publishing on npm and PyPI instead of long-lived tokens in CI secrets, and restrict which workflows and refs can publish. See our CI/CD Pipeline Identity Security Guide.
  • Protect release workflows from earlier steps. Isolate publish steps in their own jobs, and treat writes to GITHUB_ENV and BASH_ENV as suspicious. Require reviewed, signed commits on release branches and tags.
  • Give agent runtimes a minimal environment. Do not run agent gateways with developer home directories or broad credentials, and scope the keys they hold. See our Secrets Management Guide.
  • Check published artefacts against source. Alert when a published version does not match a commit, the signal that exposed this attack.

Frequently asked questions

Which MemTensor packages were compromised?

npm @memtensor/memos-cloud-openclaw-plugin versions 0.1.21, 0.1.23 and 0.1.25, and PyPI MemoryOS version 2.0.34, all published on 23 September 2026. SafeDep found no new versions of other @memtensor packages that day.

How did the attacker publish the malicious versions?

SafeDep traced commits, pushed as the Memtensor-AI GitHub account, that made MemTensor's release workflows run an attacker script through BASH_ENV. The script captured the npm token and PyPI API token during the publish steps. For PyPI, the project's own workflow then uploaded the malicious build. How the attacker got push access is not confirmed.

What should I do if I installed an affected version?

Remove it, pin to the last clean version, stop any sckit processes, block skyleen[.]fr, and rotate every credential reachable from the affected user environment, including registry tokens, source control tokens, SSH keys and cloud credentials.

ChainDrop npm worm 2026 · Miasma and Hades supply chain worms · Mastra npm supply chain attack · AI Agent Memory Security Guide · CI/CD Pipeline Identity Security Guide

How NHI Mgmt Group can help

Securing Non-Human Identities (NHIs), including AI agents, is becoming increasingly crucial as attackers hijack CI publish tokens and plant stealers inside agent runtimes. Our NHI Foundation Level Training Course gives teams the practical grounding to protect those tokens and keys.

References

Explore further

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 29 September 2026.
    Based on the public sources listed under References. Details may change as investigations continue.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org