MemOS supply-chain worm sckit steals developer tokens
Researchers at Semgrep found the sckit malware embedded in legitimate npm and PyPI releases of MemTensor's MemOS AI memory framework. It stays dormant during installation and triggers on Python imports or OpenClaw startup, scanning for npm, PyPI, GitHub, cloud and Slack tokens and sending them to skyleen.fr domains.
- sckit was embedded in official MemOS npm and PyPI releases
- Payload triggers on Python imports or OpenClaw gateway startup
- It scans for npm, PyPI, GitHub, AWS, Slack tokens and SSH keys
- Stolen data is sent to skyleen.fr; theft counts undisclosed
Read next
Security