Malicious MemTensor npm and PyPI Releases Target Developer Credentials

· Original article ↗

Summary

Four compromised MemTensor package releases bundle cross-platform Go payloads that launch on plugin startup, memory recall, or Python import. Static analysis shows they search developer homes and environments for secrets and communicate with C2 servers under skyleen[.]ф

Key points

  • The affected releases are npm @memtensor/memos-cloud-openclaw-plugin versions 0.1.21, 0.1.23 and 0.1.25, plus PyPI MemoryOS 2.0.34. These were the latest releases on their registries at the time of the report.
  • The bundled sckit payload runs when the npm plugin starts and on each memory recall, or when the Python package is imported; it supports Linux, macOS and Windows on x64 and arm64.
  • Static analysis indicates the payload searches home directories and environment variables for credentials, including npm, PyPI, GitHub, GitLab, AWS, Vault and SSH secrets, and reports to C2 servers under skyleen[.]fr.
  • Malicious code appeared in commits to MemTensor's GitHub repositories. The researchers could not confirm how the attacker gained registry publishing access; the investigation is ongoing.
  • Treat hosts that loaded the affected releases as compromised: remove or pin the packages, rotate accessible secrets, check for running sckit processes, and review network logs and package publishing activity.
  • The report warns that prompts processed by an affected npm plugin may have been exposed to the payload. Strings in the binaries also suggest possible package republishing with stolen registry tokens, but that behavior is not confirmed.

Article Details

Attack Vectors
  • On 2026-09-23, malicious releases of @memtensor/memos-cloud-openclaw-plugin and MemoryOS were published to npm and PyPI. Socket could not confirm how the attacker gained publishing access.
  • The malicious code also appeared in commits to MemTensor's GitHub repositories. Both commits added sckit binaries and launch code and altered release tooling to target registry publish tokens.
  • The npm plugin launches sckit when the OpenClaw gateway starts and on each memory recall, passing the user's prompt through SCKIT_EVENT_TEXT.
  • Importing memos from MemoryOS 2.0.34 is sufficient to launch sckit once per process. Both packages pass the host's environment to the binary.
  • According to Socket's static analysis, sckit searches home directories and environment variables for secrets and reports to C2 servers under skyleen[.]fr. Socket had not executed the samples.
Defensive Notes
  • Treat hosts that loaded npm versions 0.1.21, 0.1.23 or 0.1.25, or imported PyPI MemoryOS 2.0.34, as compromised; this includes developer machines, CI runners and test containers.
  • Search dependency records for affected versions. Uninstall them or pin the npm package to 0.1.20 and MemoryOS to 2.0.33 until a verified clean release is available.
  • Rotate secrets accessible from the affected user's home directory or environment, including registry publish tokens and other credentials.
  • Stop running sckit processes and remove affected package directories and the ~/.openclaw/.cache/runtime/ and ~/.memos/.cache/runtime/ directories.
  • Block skyleen[.]fr and its subdomains, and review DNS, proxy and egress logs for connections since 2026-09-23.
  • Review potentially exposed prompts and, where affected hosts held publish tokens, check package releases for unauthorized versions.

Indicators of compromise

TypeIndicatorContext
DOMAINskyleen[.]frParent domain of the observed sckit C2 servers; Socket recommends blocking it and its subdomains.
HOSTNAME0b48fafd6fbe[.]skyleen[.]frObserved C2 server for the malicious npm package.
HOSTNAME10729e014d0e[.]skyleen[.]frEndpoint associated with the malicious PyPI CI helper files.
HOSTNAME266297c6df27[.]skyleen[.]frObserved C2 server for the malicious npm package.
HOSTNAME73376a079d87[.]skyleen[.]frObserved C2 server for the malicious PyPI package.
HOSTNAME8a8acaf167b3[.]skyleen[.]frObserved C2 server for the malicious npm package.
HOSTNAMEc747d139e7e9[.]skyleen[.]frObserved C2 server for the malicious PyPI package.
HOSTNAMEd4f77a3a8cb0[.]skyleen[.]frObserved C2 server for the malicious PyPI package.
SHA25616de381deb978744535b10f68fe15165251374b86eef18ffc2c47f61ea673047Windows amd64 sckit binary in malicious MemoryOS 2.0.34.
SHA256381ac6dc1715d9298fe81b2a53a11f7b7d78e361ee3a6619ad54f8c4b062cc18Linux amd64 sckit binary in the malicious npm releases.
SHA25639ee644406829a4b630b31759c20478bc22d576d6a59b253ed86f72c360aa5efMalicious MemoryOS 2.0.34 PyPI wheel.
SHA2565405e330507602e803f7dd6f2a9d4555aec8558ab222b51413594a962da6888amacOS arm64 sckit binary in malicious MemoryOS 2.0.34.
SHA25656cd3416d2ec2aa7e7cec2a06010cf0b58eb09c0a5486809df52afeaca8f14beWindows amd64 sckit binary in the malicious npm releases.
SHA25665faf8ccbcf5b34eb4f72c71bf82815fa9c1e2f947b9c898491540e866132c31macOS amd64 sckit binary in the malicious npm releases.
SHA2568f647f17a1934679c4095e21bee2b9bd83e28476603758bc91408a0c8443e3b4Linux arm64 sckit binary in malicious MemoryOS 2.0.34.
SHA25692b46d18fc553c494eda714f204459edb74c205bf53b18a9092bcf02c7a6c5beMalicious MemoryOS 2.0.34 PyPI source distribution.
SHA2569de0d5b0ca184f71f630be5781d134998883a02d5d7bc65aeb9559d8f9efb364macOS amd64 sckit binary in malicious MemoryOS 2.0.34.
SHA256c1b0998347b489582bae7b7f4930f9831d9ef4b6bc150cfd488ee1a43272dd36Linux amd64 sckit binary in malicious MemoryOS 2.0.34.
SHA256d6b3e77c36ee8017c9bf30d1da7218ec0ea843768d313eb8e35845c8a9b38a26Windows arm64 sckit binary in the malicious npm releases.
SHA256e077c387b223811064b7bbc5a55a0182fca9bf50894f949ff284d4be87d44b26Linux arm64 sckit binary in the malicious npm releases.
SHA256f7c4014e284f3d56c452b8b222a287c54f73dc4a40a7e022e765ac8376362947Windows arm64 sckit binary in malicious MemoryOS 2.0.34.
SHA256f8ccdd1da7dff1aef16377a2842bc7acf7c516e32122dd6e42dc4a4e57653fcemacOS arm64 sckit binary in the malicious npm releases.
URLhxxps[:]//10729e014d0e[.]skyleen[.]fr/eb57efaa7365698fc1e4decc/initial-ci-v2Specific endpoint listed for the malicious PyPI CI helper.

MITRE ATT&CK

Malware

Vendors

Products

Related Articles