On 23 September 2026, an attacker published malicious versions of two MemTensor packages: the OpenClaw memory plugin @memtensor/memos-cloud-openclaw-plugin on npm, and the MemOS Python library MemoryOS on PyPI. Both carried the same Go implant, sckit. It runs in the background whenever the package loads, collects credentials from the developer's home directory and sends them to servers under skyleen[.]fr. The attacker did not steal the maintainers' passwords. They changed MemTensor's own GitHub Actions release pipelines so that the npm and PyPI publish tokens were captured as the workflows ran, then used the project's real release process to ship the backdoor. Because the npm plugin runs inside an AI agent's memory layer, the implant fired on every memory recall with the agent's full environment. The binary also contains code to spread itself using any publish tokens it finds.
Key takeaways
- Malicious versions: npm
@memtensor/memos-cloud-openclaw-plugin0.1.21, 0.1.23 and 0.1.25, and PyPIMemoryOS2.0.34, all published on 23 September 2026. A plain install pulled the backdoor, and--ignore-scriptsdid not help because the payload runs when the code loads. - SafeDep traced how the tokens were stolen. Commits pushed as the
Memtensor-AIaccount made the release workflows load an attacker script throughBASH_ENV, which handed the npm token and the PyPI API token to the implant before publishing. - The sckit implant targets npm and PyPI tokens, GitHub and GitLab tokens, SSH keys, AWS and other cloud CLI credentials, HashiCorp Vault tokens, Hugging Face credentials, JWTs and
.envsecrets under the home directory. - In the npm plugin, the implant starts when the OpenClaw gateway starts and again on every memory recall. It receives the full environment and the user's prompt text.
- The binary includes code to copy itself into other repositories and packages that stolen credentials can reach. SafeDep had not seen further spread at the time of writing.
At a glance
| Organisations | MemTensor (maintainer of MemOS and the OpenClaw memory plugin); developers and AI agent deployments that installed the affected versions |
|---|---|
| When | Malicious releases on 23 September 2026, between 02:23 and 05:25 UTC; reported by SafeDep and Socket the same day |
| Attacker | Unknown. The npm versions came from the existing maintainer account leason1974; the GitHub changes were pushed as Memtensor-AI, probably with a stolen token (unconfirmed) |
| Entry point | Commits to MemTensor's GitHub repositories that hijacked GitHub Actions release workflows via BASH_ENV |
| Identities abused | The Memtensor-AI GitHub account; the npm publish token and PyPI API token stored as GitHub Actions secrets; developer credentials harvested by the implant |
| Impact | Backdoored packages published to npm and PyPI; credential theft from every host that loaded them; worm capability to republish other packages |
| Category | NHI, Agentic AI and AI agents. Incident class: confirmed NHI breach (CI publish tokens stolen and used; credential stealer shipped to users) |
What happened
MemOS is an open-source memory framework for AI agents from MemTensor. Its main GitHub repository has about 11,500 stars, according to Socket. The OpenClaw plugin connects the OpenClaw agent gateway to MemOS's cloud memory. SafeDep's monitoring flagged a GitHub issue reporting that plugin versions 0.1.21 and 0.1.23 did not match any commit in the repository. SafeDep then reconstructed what happened from repository events, commit metadata and registry data.
Between 00:48 and 02:03 UTC on 23 September, the Memtensor-AI account created, pushed and deleted a release branch five times on the plugin repository. The commits changed a validation script so that it wrote a BASH_ENV entry into the GitHub Actions environment. Bash runs the file named in BASH_ENV before any non-interactive script, so the attacker's script ran just before the real npm publish step. It passed the npm token to the sckit binary, deleted itself, and failed the step so that nothing was published from that run. Twenty minutes later, npm version 0.1.21 appeared with the implant. On the MemOS repository, a commit added the sckit binaries and a custom Poetry build backend that used the same BASH_ENV trick to capture the PyPI API token. A second commit then let MemTensor's own workflow build the malicious package and upload it to PyPI with the project's real token. SafeDep found that the GitHub Actions API returned no workflow runs for the repositories after early September, and infers that the run logs were deleted. It could not confirm how the attacker got push access as Memtensor-AI, and says a stolen token is the most likely explanation.
Once installed, the implant starts without any install hook. In the npm plugin it launches when the OpenClaw gateway starts and again on every memory recall, detached, with the full environment and the user's prompt text. In MemoryOS it launches when the library configures logging, which almost every import path does. Socket reports that sckit searches the home directory for npm, PyPI, GitHub, GitLab and AWS credentials, HashiCorp Vault tokens, SSH keys, Hugging Face credentials and JSON Web Tokens, and sends them to skyleen[.]fr subdomains. SafeDep says the binary contains code to copy itself into other repositories and packages that stolen credentials can reach.
Timeline
| Date (UTC) | Event |
|---|---|
| 23 September 2026, 00:48 to 02:03 | Memtensor-AI pushes and deletes a release branch five times on the OpenClaw plugin repository. |
| 23 September 2026, 02:23 | npm 0.1.21 published with the sckit binary. |
| 23 September 2026, 03:17 | Commit on MemTensor/MemOS adds sckit and a CI token stealer. |
| 23 September 2026, 03:49 | npm 0.1.23 (malicious) published. |
| 23 September 2026, 04:17 | A researcher opens an issue: published versions do not match any commit. |
| 23 September 2026, 04:36 | npm 0.1.25 (malicious) published. |
| 23 September 2026, 05:25 | MemoryOS 2.0.34 uploaded to PyPI with the implant. |
How it happened: the identity attack path
- A trusted GitHub identity. The attacker pushed commits as Memtensor-AI, an account that had contributed to the project before. How they got its access is unconfirmed.
- Release workflows that trusted repository code. Scripts that ran earlier in the release job could change the environment of later steps, including the publish step.
- Publish tokens captured in the pipeline. Through
BASH_ENV, the attacker's script ran inside the publish steps and took the npm token and PyPI API token as the workflows handed them over. - The real release process, abused. For PyPI, the attacker let MemTensor's own workflow and token upload the malicious build, so the package looked like a normal release.
- An implant inside the agent runtime. The plugin ran in the OpenClaw gateway and fired on every memory recall, inheriting the agent's environment and credentials.
- Stolen tokens become the next foothold. The implant hunted for more publish tokens and included code to republish other packages, the pattern of recent package worms.
Impact
- Packages: three malicious npm versions and one malicious PyPI version. At collection time, 0.1.25 held npm's "latest" tag and 2.0.34 was the newest PyPI release.
- Credentials: any host that loaded an affected version should treat every credential in its home directory as exposed, including registry tokens, source control tokens, SSH keys, cloud credentials and Vault tokens.
- Spread: worm capability present. SafeDep had not seen confirmed downstream spread, but warns the affected list can grow.
- Attribution: unknown actor. Socket could not confirm how publishing access was obtained.
What this means for NHI and AI agent security
This attack is non-human identities from start to finish. It began with a machine-used GitHub account, ran through CI secrets, hijacked the publish tokens that registries trust, and ended with an implant harvesting the tokens and keys on developer and agent hosts. Our timeline shows the same shape in Shai-Hulud, ChainDrop and Miasma and Hades. Long-lived publish tokens stored as CI secrets remain one of the most valuable targets in the software supply chain.
What is new is where the implant sat. An agent memory component runs inside the agent's process on every recall, with the agent's environment. That environment often holds model provider keys, tool credentials and cloud access. Compromising a memory library is therefore a way into every credential the agent can use. Components inside agent runtimes need the same supply-chain scrutiny as anything else that runs with production secrets. Our AI Agent Memory Security Guide and AI Supply Chain and AI-BOM Guide cover this.
Recommendations
- Remove and pin. Uninstall the affected versions and pin to npm 0.1.20 and PyPI 2.0.33, the last clean releases named by Socket. Kill any running sckit processes.
- Rotate everything on affected hosts. Treat npm and PyPI tokens, GitHub and GitLab tokens, SSH keys, cloud credentials, Vault tokens and
.envsecrets as exposed. Use our Leaked Credential Response Playbook. - Replace publish tokens with trusted publishing. Use OIDC-based trusted publishing on npm and PyPI instead of long-lived tokens in CI secrets, and restrict which workflows and refs can publish. See our CI/CD Pipeline Identity Security Guide.
- Protect release workflows from earlier steps. Isolate publish steps in their own jobs, and treat writes to
GITHUB_ENVandBASH_ENVas suspicious. Require reviewed, signed commits on release branches and tags. - Give agent runtimes a minimal environment. Do not run agent gateways with developer home directories or broad credentials, and scope the keys they hold. See our Secrets Management Guide.
- Check published artefacts against source. Alert when a published version does not match a commit, the signal that exposed this attack.
Frequently asked questions
Which MemTensor packages were compromised?
npm @memtensor/memos-cloud-openclaw-plugin versions 0.1.21, 0.1.23 and 0.1.25, and PyPI MemoryOS version 2.0.34, all published on 23 September 2026. SafeDep found no new versions of other @memtensor packages that day.
How did the attacker publish the malicious versions?
SafeDep traced commits, pushed as the Memtensor-AI GitHub account, that made MemTensor's release workflows run an attacker script through BASH_ENV. The script captured the npm token and PyPI API token during the publish steps. For PyPI, the project's own workflow then uploaded the malicious build. How the attacker got push access is not confirmed.
What should I do if I installed an affected version?
Remove it, pin to the last clean version, stop any sckit processes, block skyleen[.]fr, and rotate every credential reachable from the affected user environment, including registry tokens, source control tokens, SSH keys and cloud credentials.
Related NHI Mgmt Group resources
ChainDrop npm worm 2026 · Miasma and Hades supply chain worms · Mastra npm supply chain attack · AI Agent Memory Security Guide · CI/CD Pipeline Identity Security Guide
How NHI Mgmt Group can help
Securing Non-Human Identities (NHIs), including AI agents, is becoming increasingly crucial as attackers hijack CI publish tokens and plant stealers inside agent runtimes. Our NHI Foundation Level Training Course gives teams the practical grounding to protect those tokens and keys.
References
- SafeDep: MemTensor npm and PyPI Packages Hit by a Go Worm (23 September 2026)
- SecurityOnline: MemTensor MemOS Compromise Exposes AI Developer Secrets (23 September 2026)
- Decryption Digest: MemTensor npm PyPI Supply Chain Attack: Rotate Now (25 September 2026)