A worm on npm and PyPI stole credentials through packages of MemOS, a memory system for AI agents
Compromised versions of an npm plugin and of the MemoryOS package on PyPI were published on Sept. 23, between 02:23 and 05:55 UTC, from a maintainer's account, per Forkast.
The payload is sckit, a Go credential stealer that looks for 13 kinds of secrets, including npm, PyPI, GitHub and Hugging Face tokens, AWS keys, Stripe live keys and SSH keys. The affected project, MemTensor's MemOS, has 11,500 GitHub stars. Semgrep and StepSecurity analyzed the attack, per Forkast.
The affected versions are 0.1.21, 0.1.23 and 0.1.25 of @memtensor/memos-cloud-openclaw-plugin on npm and 2.0.34 of MemoryOS on PyPI. Forkast recommends pinning versions 0.1.20 and 2.0.33, rotating all exposed credentials and blocking the command-and-control domain.
Sources: Forkast