20:20
2026-09-25
forkast.news
ai-safety
The First Supply-Chain Worm Targeting AI Agent Memory Infrastructure Just Hit npm and PyPI
Malicious versions of MemTensor's MemOS memory framework for LLMs and AI agents appeared on npm and PyPI between 02:23 UTC and 05:55 UTC on September 23, 2026, carrying a cross-platform Go credential …