# MemTensor MemOS Backdoored: Audit Your AI Agent Memory Packages Now

> Source: <https://byteiota.com/memtensor-memos-backdoored-audit-your-ai-agent-memory-packages-now/>
> Published: 2026-09-28 02:13:53+00:00

Between 02:23 and 05:55 UTC on September 23, two MemTensor packages on npm and PyPI were replaced with versions carrying sckit, a cross-platform Go credential stealer built to spread. If your project imports `@memtensor/memos-cloud-openclaw-plugin` or `MemoryOS` — and has npm tokens, GitHub credentials, SSH keys, or cloud secrets anywhere nearby — those credentials may already be gone. The campaign’s kill date is **October 23, 2026**. It is still running.

## Check If You Are Affected Right Now

Two commands. Run both.

```
# npm
npm ls @memtensor/memos-cloud-openclaw-plugin

# PyPI
pip show MemoryOS
```

If npm reports versions 0.1.21, 0.1.23, or 0.1.25, you are affected. If PyPI reports version 2.0.34, you are affected. Clean versions are **0.1.20** for npm and **2.0.33** for PyPI.

## How sckit Works — and Why –ignore-scripts Won’t Save You

sckit does not fire during installation. It fires at **runtime**, the moment your code imports the package. In OpenClaw, it re-executes on every memory recall operation, running as a persistent background process throughout your agent’s session. The practical consequence: `npm install --ignore-scripts`, the standard supply chain defense, does nothing here. If you loaded an affected version, the payload ran.

Once running, sckit harvests credentials from your home directory and ships them to six subdomains under `skyleen.fr` (IP 139.84.223.178). The credential sweep is comprehensive: npm and PyPI tokens, GitHub and GitLab tokens, SSH private keys, AWS, GCP, and Azure credentials, Hugging Face tokens, Slack tokens, Stripe keys, and SendGrid API keys. It reads the files developers trust most — `.npmrc`, `.pypirc`, `~/.aws/credentials`, `~/.ssh/`, and cloud CLI token caches.

What makes sckit a worm rather than just a stealer: it carries self-propagation templates for npm packages, PyPI packages, and GitHub Actions workflows. It uses stolen publish tokens to push compromised versions to other packages you control. No confirmed downstream spread has been reported as of September 28 — but the campaign runs for another three weeks.

## How the Attack Got In

This was not a typosquat or a stolen maintainer account. The attacker pushed commits to MemTensor’s GitHub repository that modified the GitHub Actions release pipelines. The malicious commits made the release job forward its npm and PyPI publish tokens to an attacker-controlled server before the publish step completed. The attacker then used those tokens directly to push the backdoored versions.

This is the same CI/CD token-theft pattern seen in [TeamPCP](https://byteiota.com/teampcp-supply-chain-worm-bitwarden/) and [ChainDrop](https://byteiota.com/chaindrop-worm-npm-packages/), applied here to an AI memory framework that runs inside production agent sessions. The attack surface has shifted from “packages developers install once” to “packages that agents load continuously with elevated access to the filesystem and context.”

## Why AI Memory Packages Are Higher-Risk Targets

MemOS has 11,500 GitHub stars. OpenClaw — its primary integration — has 357,000. These are not edge-case tools. They run in long-lived production AI agent environments, with access to the agent’s full context window, filesystem, and whatever credentials the agent needs to do its job. A compromised memory plugin is not a compromised build dependency; it is a compromised component with persistent access to everything your agent touches.

According to [SafeDep’s analysis](https://safedep.io/memtensor-sckit-worm-npm-pypi/), this is the first documented supply chain worm specifically targeting AI agent memory infrastructure. It will not be the last.

## Remediate Now

**Remove the malicious versions and pin to clean ones:**

```
npm uninstall @memtensor/memos-cloud-openclaw-plugin
npm install @memtensor/memos-cloud-openclaw-plugin@0.1.20

pip uninstall MemoryOS -y
pip install "MemoryOS==2.0.33"
```

**Check for running sckit processes:**

```
ps aux | grep -E 'sckit|stage0|config64'
```

**Block C2 traffic** at your firewall or DNS resolver: all subdomains of `skyleen.fr` and IP `139.84.223.178`.

**Rotate credentials.** If any affected version was imported in your environment, treat all credentials accessible from that session as compromised: npm token, PyPI token, GitHub PATs, AWS access keys, GCP service account keys, SSH keys, and any API keys stored in environment variables or `~/.config/`. Rotation is not optional — stolen credentials exfiltrate silently with no sign-of-life in your logs.

**Audit your CI/CD pipelines.** Review GitHub Actions workflow files for recent modifications to release and publish jobs. Switch npm and PyPI publishing to short-lived OIDC tokens. Require code review on any commit that touches `.github/workflows/`. [StepSecurity’s guide](https://www.stepsecurity.io/blog/sckit-supply-chain-worm-hits-memtensor-npm-pypi-scopes) covers the specific hardening steps for this attack pattern.

## The Lesson That Outlasts This Incident

The threat model for AI agent packages is different from ordinary developer dependencies. These packages run continuously, with broad access, inside live agent sessions. Install-time scanning does not catch runtime payloads. If you depend on memory, tool, or integration libraries in production agents, [runtime behavior monitoring](https://socket.dev/blog/memtensor-compromise) — not just lockfile pinning — is now table stakes.
