Web Programming

Patch nowJS & TypeScript

Compromised MemTensor packages on npm and PyPI steal developer credentials

Issue #2

On September 23 compromised releases of a MemTensor npm plugin and of MemoryOS on PyPI bundled a Go binary that searches $HOME for credentials.

Karlen TriminoSenior Full-Stack Engineer

Leer en español
Photo: Karola G / Pexels

What to do

Pin to 0.1.20 and 2.0.33 or remove the packages, then rotate secrets.

Key facts

Affected
@memtensor/memos-cloud-openclaw-plugin 0.1.21, 0.1.23, 0.1.25; MemoryOS 2.0.34
Not affected
0.1.20 (npm), 2.0.33 (PyPI)

Compromised releases of @memtensor/memos-cloud-openclaw-plugin (0.1.21, 0.1.23, 0.1.25) on npm and MemoryOS 2.0.34 on PyPI bundled a Go binary that searches $HOME for npm, PyPI, GitHub, AWS and SSH credentials. Pin to 0.1.20 and 2.0.33 or remove them, then rotate secrets.

Sources