chiprook
← Security
SecuritySeptember 26, 2026, 09:13

MemOS supply-chain worm sckit steals developer tokens

Researchers at Semgrep found the sckit malware embedded in legitimate npm and PyPI releases of MemTensor's MemOS AI memory framework. It stays dormant during installation and triggers on Python imports or OpenClaw startup, scanning for npm, PyPI, GitHub, cloud and Slack tokens and sending them to skyleen.fr domains.

MemOS supply-chain worm sckit steals developer tokens
#MemTensor#MemOS#OpenClaw#Npm
Read next
Security

Compromised MemTensor packages push sckit credential stealer via npm and PyPI

Security

Shai-Hulud npm worm ran code just by opening a folder

Security

ChainDrop npm Worm Hijacks 444 Packages with 2B Monthly Downloads

Security

Malicious npm Package Poses as Twilio Security Tool, Steals Credentials