MemTensor MemOS packages compromised with a credential stealer
Poisoned releases of an LLM memory framework stole developer and cloud credentials the moment they loaded.
· Socket · Research by Karlo Zanki (Socket Threat Research)

Malicious releases of MemTensor's MemOS packages on npm and PyPI shipped sckit, a Go credential stealer that runs on import and sends npm, PyPI, GitHub, cloud and SSH secrets to skyleen[.]fr. Safe versions: npm 0.1.20, PyPI 2.0.33.
01What happened
Socket Threat Research reported on September 23, 2026 that malicious versions of MemTensor's MemOS packages were published to npm and PyPI. MemOS is an open-source memory framework for LLMs and AI agents with about 11,500 GitHub stars. Socket could not confirm how the attacker gained publishing access.
02How it works
The malicious releases bundle sckit, cross-platform Go binaries that search for credential files such as .npmrc, .vault-token and SSH keys, and for secrets in environment variables. The npm plugin starts the stealer when the OpenClaw gateway starts and on every memory recall with the user's prompt text, and the PyPI package runs it as soon as the memos module is imported. Stolen AWS keys, GitHub and GitLab tokens and npm and PyPI credentials go to command servers under skyleen[.]fr.
03Who is affected
Anyone who installed npm @memtensor/memos-cloud-openclaw-plugin 0.1.21, 0.1.23 or 0.1.25, or PyPI MemoryOS 2.0.34.
04What to do
Pin npm to 0.1.20 or earlier and PyPI to 2.0.33 or earlier, kill any sckit process, rotate every secret reachable from affected home directories, and block skyleen[.]fr while reviewing connection logs since September 23.
Questions people ask
- Which MemOS package versions are malicious?
- The malicious MemOS releases are npm @memtensor/memos-cloud-openclaw-plugin versions 0.1.21, 0.1.23 and 0.1.25, and PyPI MemoryOS version 2.0.34, according to Socket Threat Research. Socket lists npm 0.1.20 and earlier and PyPI 2.0.33 and earlier as safe. Check lockfiles and installed environments, not just declared ranges.
- What should I rotate after installing the compromised MemOS package?
- After installing a compromised MemOS package, rotate every secret the sckit stealer could reach from the affected home directory and environment. Socket says sckit targets npm and PyPI tokens, GitHub and GitLab tokens, AWS keys, Vault tokens and SSH keys. Also kill sckit processes, delete package caches and review logs for connections to skyleen[.]fr.
- Does the MemOS stealer run without an install script?
- The MemOS stealer does not depend on install hooks, according to Socket. The PyPI MemoryOS release runs sckit as soon as the memos module is imported, and the npm OpenClaw plugin starts it when the OpenClaw gateway starts and on every memory recall. Blocking install scripts alone would not have stopped this compromise.
Sources 2 links, all fetched
- 1socket.devSocket Analysis
- 2labs.cloudsecurityalliance.orgCSA Research Note