Malicious MemTensor npm and PyPI Releases Target Developer Credentials

Summary
Four compromised MemTensor package releases bundle cross-platform Go payloads that launch on plugin startup, memory recall, or Python import. Static analysis shows they search developer homes and environments for secrets and communicate with C2 servers under skyleen[.]ф
Key points
- The affected releases are npm @memtensor/memos-cloud-openclaw-plugin versions 0.1.21, 0.1.23 and 0.1.25, plus PyPI MemoryOS 2.0.34. These were the latest releases on their registries at the time of the report.
- The bundled sckit payload runs when the npm plugin starts and on each memory recall, or when the Python package is imported; it supports Linux, macOS and Windows on x64 and arm64.
- Static analysis indicates the payload searches home directories and environment variables for credentials, including npm, PyPI, GitHub, GitLab, AWS, Vault and SSH secrets, and reports to C2 servers under skyleen[.]fr.
- Malicious code appeared in commits to MemTensor's GitHub repositories. The researchers could not confirm how the attacker gained registry publishing access; the investigation is ongoing.
- Treat hosts that loaded the affected releases as compromised: remove or pin the packages, rotate accessible secrets, check for running sckit processes, and review network logs and package publishing activity.
- The report warns that prompts processed by an affected npm plugin may have been exposed to the payload. Strings in the binaries also suggest possible package republishing with stolen registry tokens, but that behavior is not confirmed.
Article Details
- Attack Vectors
- On 2026-09-23, malicious releases of @memtensor/memos-cloud-openclaw-plugin and MemoryOS were published to npm and PyPI. Socket could not confirm how the attacker gained publishing access.
- The malicious code also appeared in commits to MemTensor's GitHub repositories. Both commits added sckit binaries and launch code and altered release tooling to target registry publish tokens.
- The npm plugin launches sckit when the OpenClaw gateway starts and on each memory recall, passing the user's prompt through SCKIT_EVENT_TEXT.
- Importing memos from MemoryOS 2.0.34 is sufficient to launch sckit once per process. Both packages pass the host's environment to the binary.
- According to Socket's static analysis, sckit searches home directories and environment variables for secrets and reports to C2 servers under skyleen[.]fr. Socket had not executed the samples.
- Defensive Notes
- Treat hosts that loaded npm versions 0.1.21, 0.1.23 or 0.1.25, or imported PyPI MemoryOS 2.0.34, as compromised; this includes developer machines, CI runners and test containers.
- Search dependency records for affected versions. Uninstall them or pin the npm package to 0.1.20 and MemoryOS to 2.0.33 until a verified clean release is available.
- Rotate secrets accessible from the affected user's home directory or environment, including registry publish tokens and other credentials.
- Stop running sckit processes and remove affected package directories and the ~/.openclaw/.cache/runtime/ and ~/.memos/.cache/runtime/ directories.
- Block skyleen[.]fr and its subdomains, and review DNS, proxy and egress logs for connections since 2026-09-23.
- Review potentially exposed prompts and, where affected hosts held publish tokens, check package releases for unauthorized versions.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | skyleen[.]fr | Parent domain of the observed sckit C2 servers; Socket recommends blocking it and its subdomains. |
| HOSTNAME | 0b48fafd6fbe[.]skyleen[.]fr | Observed C2 server for the malicious npm package. |
| HOSTNAME | 10729e014d0e[.]skyleen[.]fr | Endpoint associated with the malicious PyPI CI helper files. |
| HOSTNAME | 266297c6df27[.]skyleen[.]fr | Observed C2 server for the malicious npm package. |
| HOSTNAME | 73376a079d87[.]skyleen[.]fr | Observed C2 server for the malicious PyPI package. |
| HOSTNAME | 8a8acaf167b3[.]skyleen[.]fr | Observed C2 server for the malicious npm package. |
| HOSTNAME | c747d139e7e9[.]skyleen[.]fr | Observed C2 server for the malicious PyPI package. |
| HOSTNAME | d4f77a3a8cb0[.]skyleen[.]fr | Observed C2 server for the malicious PyPI package. |
| SHA256 | 16de381deb978744535b10f68fe15165251374b86eef18ffc2c47f61ea673047 | Windows amd64 sckit binary in malicious MemoryOS 2.0.34. |
| SHA256 | 381ac6dc1715d9298fe81b2a53a11f7b7d78e361ee3a6619ad54f8c4b062cc18 | Linux amd64 sckit binary in the malicious npm releases. |
| SHA256 | 39ee644406829a4b630b31759c20478bc22d576d6a59b253ed86f72c360aa5ef | Malicious MemoryOS 2.0.34 PyPI wheel. |
| SHA256 | 5405e330507602e803f7dd6f2a9d4555aec8558ab222b51413594a962da6888a | macOS arm64 sckit binary in malicious MemoryOS 2.0.34. |
| SHA256 | 56cd3416d2ec2aa7e7cec2a06010cf0b58eb09c0a5486809df52afeaca8f14be | Windows amd64 sckit binary in the malicious npm releases. |
| SHA256 | 65faf8ccbcf5b34eb4f72c71bf82815fa9c1e2f947b9c898491540e866132c31 | macOS amd64 sckit binary in the malicious npm releases. |
| SHA256 | 8f647f17a1934679c4095e21bee2b9bd83e28476603758bc91408a0c8443e3b4 | Linux arm64 sckit binary in malicious MemoryOS 2.0.34. |
| SHA256 | 92b46d18fc553c494eda714f204459edb74c205bf53b18a9092bcf02c7a6c5be | Malicious MemoryOS 2.0.34 PyPI source distribution. |
| SHA256 | 9de0d5b0ca184f71f630be5781d134998883a02d5d7bc65aeb9559d8f9efb364 | macOS amd64 sckit binary in malicious MemoryOS 2.0.34. |
| SHA256 | c1b0998347b489582bae7b7f4930f9831d9ef4b6bc150cfd488ee1a43272dd36 | Linux amd64 sckit binary in malicious MemoryOS 2.0.34. |
| SHA256 | d6b3e77c36ee8017c9bf30d1da7218ec0ea843768d313eb8e35845c8a9b38a26 | Windows arm64 sckit binary in the malicious npm releases. |
| SHA256 | e077c387b223811064b7bbc5a55a0182fca9bf50894f949ff284d4be87d44b26 | Linux arm64 sckit binary in the malicious npm releases. |
| SHA256 | f7c4014e284f3d56c452b8b222a287c54f73dc4a40a7e022e765ac8376362947 | Windows arm64 sckit binary in malicious MemoryOS 2.0.34. |
| SHA256 | f8ccdd1da7dff1aef16377a2842bc7acf7c516e32122dd6e42dc4a4e57653fce | macOS arm64 sckit binary in the malicious npm releases. |
| URL | hxxps[:]//10729e014d0e[.]skyleen[.]fr/eb57efaa7365698fc1e4decc/initial-ci-v2 | Specific endpoint listed for the malicious PyPI CI helper. |
MITRE ATT&CK
T1041 · Exfiltration Over C2 ChannelSocket reports that sckit is configured to send discovered secrets to C2 servers under skyleen[.]fr; the finding is based on static analysis, not executed samples.T1195.001 · Compromise Software Dependencies and Development ToolsMalicious npm and PyPI releases of MemTensor packages bundled sckit binaries that launch when the packages are loaded.T1552.001 · Credentials In FilesSocket's static analysis found that sckit searches the user's home directory for credential files, including .npmrc, .vault-token and SSH secrets.
Malware
Vendors
Products
@memtensor/memos-cloud-openclaw-pluginFour malicious releases, three of the npm package @memtensor/memos-cloud-openclaw-plugin and one of the PyPI package MemoryOS, each currently the latest version on its registry, drop cross-platform Go binaries thatMemoryOSreleases, three of the npm package @memtensor/memos-cloud-openclaw-plugin and one of the PyPI package MemoryOS, each currently the latest version on its registry, drop cross-platform Go binaries that searchMemOSThe compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents.OpenClawFour malicious releases, three of the npm package @memtensor/memos-cloud-openclaw-plugin and one of the PyPI package MemoryOS, each currently the latest version on its registry, drop cross-platform Go binaries that