Skip to content

The Injection_

LIVE
LIVElast sweep UTCnext in--:--:--

[ RSS ][ JSON ][ llms.txt ]

MemoryOS (PyPI)
MemTensor MemOS packages compromised with a credential stealer
HIGHSupply chain

HIGHSupply chain

MemTensor MemOS packages compromised with a credential stealer

Poisoned releases of an LLM memory framework stole developer and cloud credentials the moment they loaded.

Affects
@memtensor/memos-cloud-openclaw-plugin, MemoryOS (PyPI), MemOS
Malicious npm
@memtensor/memos-cloud-openclaw-plugin 0.1.21, 0.1.23, 0.1.25
Malicious PyPI
MemoryOS 2.0.34
Safe versions
npm 0.1.20 or earlier; PyPI 2.0.33 or earlier
Credit
Karlo Zanki

30-day exposure by ecosystem

Coding agents
5 events
MCP & plugins
4 events
Packages & models
6 events
Assistants & apps
6 events
Labs & evals
3 events

High / criticalMediumLow / info

Incident feed

17 of 17 · newest first
  1. ClaudeAnthropic Cyber Verification Program: tiered access for defendersINFOLab safetyAnthropicAnthropic Cyber Verification Program: tiered access for defenders
  2. CVE-2026-103435MEDVulnerabilityAnthropicClaude Code: symlink race allowed writes outside the project
  3. CVE-2026-104850HIGHVulnerabilityModel Context ProtocolMCP TypeScript SDK: OAuth client could leak credentials to servers
  4. CVE-2026-102697HIGHVulnerabilityVulnCheckOllama agent mode: chained shell commands skip Bash approval
  5. GPT-6 AstraUK AISI: GPT-6 Astra attacked out-of-scope targets in simulationsINFOBenchmarkUK AI Security InstituteUK AISI: GPT-6 Astra attacked out-of-scope targets in simulations
  6. AnthropicHIGHVulnerabilityAnthropicClaude Desktop for macOS: Cowork files could run commands on open
  7. AIR SecurityAnthropic skill scanner bypassed: malicious skills marked safeMEDAttackAIR SecurityAnthropic skill scanner bypassed: malicious skills marked safe
  8. Zenity LabsSalesBleed: zero-click CRM data theft through Salesforce AgentforceMEDAttackZenity LabsSalesBleed: zero-click CRM data theft through Salesforce Agentforce
  9. MemoryOS (PyPI)MemTensor MemOS packages compromised with a credential stealerHIGHSupply chainSocketMemTensor MemOS packages compromised with a credential stealer
  10. OpenAI CodexMEDResearcharXivExplosive prompts: dormant injections fire on 'thanks' in agents
  11. Claude CodePlugin4Shell: zero-click plugin RCE in four AI coding agentsHIGHVulnerabilityAIR SecurityPlugin4Shell: zero-click plugin RCE in four AI coding agents
  12. GLM-5.3INFOBenchmarkNIST CAISICAISI: GLM-5.3 is the most cyber-capable open-weight model yet
  13. OWASP GenAI Security ProjectAgent Control Standard: an open spec for blocking agent actionsINFOToolOWASP GenAI Security ProjectAgent Control Standard: an open spec for blocking agent actions
  14. Google Threat Intelligence GroupGoogle GTIG: attackers used AI agents to run a credential campaignINFOIncidentGoogle Threat Intelligence GroupGoogle GTIG: attackers used AI agents to run a credential campaign
  15. CVE-2026-65669SQL Server Copilot: prompt injection escalates a user to sysadminHIGHVulnerabilityEmbrace The RedSQL Server Copilot: prompt injection escalates a user to sysadmin
  16. ChatGPT connectorsChatGPT sandbox: shared package cache leaked data across accountsLOWVulnerabilityCheck Point ResearchChatGPT sandbox: shared package cache leaked data across accounts
  17. AIR SecurityMCPJacking: 155 hijackable servers in the official MCP registryHIGHSupply chainAIR SecurityMCPJacking: 155 hijackable servers in the official MCP registry