chiprook
← Security
SecurityOctober 11, 2026, 09:21

MemTensor packages poisoned: AI memory plugin steals developer credentials

StepSecurity reported that an attacker used a GitHub Actions release token to push malicious MemTensor builds to npm and PyPI on 23 September 2026. The poisoned @memtensor/memos-cloud-openclaw-plugin versions 0.1.21, 0.1.23 and 0.1.25 and PyPI MemoryOS 2.0.34 harvest npm, PyPI, GitHub, GitLab, AWS and Vault tokens and send them to a command-and-control server.

MemTensor packages poisoned: AI memory plugin steals developer credentials
#MemTensor#Npm#PyPI#GitHub
Read next
Security

Compromised MemTensor packages push sckit credential stealer via npm and PyPI

Security

Tensorlake npm package compromised to spread Shai-Hulud credential-stealing worm

Security

Malicious npm Package Poses as Twilio Security Tool, Steals Credentials

Security

Slopsquatting: AI agents install packages attackers registered in advance