Compromised releases of @memtensor/memos-cloud-openclaw-plugin (0.1.21, 0.1.23, 0.1.25) on npm and MemoryOS 2.0.34 on PyPI bundled a Go binary that searches $HOME for npm, PyPI, GitHub, AWS and SSH credentials. Pin to 0.1.20 and 2.0.33 or remove them, then rotate secrets.