MemTensor packages poisoned: AI memory plugin steals developer credentials
StepSecurity reported that an attacker used a GitHub Actions release token to push malicious MemTensor builds to npm and PyPI on 23 September 2026. The poisoned @memtensor/memos-cloud-openclaw-plugin versions 0.1.21, 0.1.23 and 0.1.25 and PyPI MemoryOS 2.0.34 harvest npm, PyPI, GitHub, GitLab, AWS and Vault tokens and send them to a command-and-control server.
- Malicious versions: npm 0.1.21, 0.1.23, 0.1.25 and PyPI MemoryOS 2.0.34
- Steals npm, PyPI, GitHub, GitLab, AWS and Vault tokens from developer machines
- Payload ran on OpenClaw gateway startup and on every memory recall
- Version 0.1.25 was tagged latest and poisoned builds were republished after removal
Read next
Security