Case · DiggingBeagle record

Compromised MemTensor OpenClaw memory plugin loaded sckit credential stealer

On September 23, 2026, malicious releases of the legitimate MemTensor OpenClaw memory plugin and MemoryOS contained the `sckit` Go implant. This was a publisher/package compromise rather than a look-alike extension: normal gateway startup launched the bundled payload with the host environment, and memory recall launched it again with the current user prompt. OSV documents home-directory credential collection and communication with `skyleen.fr`; StepSecurity establishes prompt transfer into the malicious child process but not successful off-host transmission of every prompt. The release sequence alternated malicious and clean versions, so package replacement alone is not a complete incident response: reachable credentials and publishing authority also require treatment.

Assessment profile

Assessment method
Setting
production
Exploitation
observed live
Evidence
Grade B
Remediation
mitigation available
Basis and provenance

Multiple package analyses agree on the malicious published versions and credential-stealing implant, and StepSecurity reproduces the OpenClaw execution path. Victim execution counts, complete prompt exfiltration and the attacker's initial access route remain unresolved, so impact is left unbanded.

Assessed Oct 5, 2026 using diggingbeagle.assessment/1.

Timeline

  1. Sep 23, 2026
    disclosure

    Independent package analyses documented the MemTensor compromise

    OSV, SafeDep and StepSecurity documented the malicious releases, credential-stealing behavior and OpenClaw execution path.

  2. Sep 23, 2026
    release

    Malicious OpenClaw plugin version 0.1.21 published

    SafeDep's reconstructed npm timeline identifies version 0.1.21 as malicious.

  3. Sep 23, 2026
    release

    Malicious version 0.1.23 followed a clean 0.1.22 release

    SafeDep recorded clean 0.1.22 at 03:45:44 UTC and malicious 0.1.23 minutes later.

  4. Sep 23, 2026
    release

    Malicious version 0.1.25 followed a clean 0.1.24 release

    SafeDep recorded clean 0.1.24 at 04:33:30 UTC and malicious 0.1.25 minutes later.

Claims & evidence

CLM-MEMTENSOR-PROMPT-PATHStepSecurity's reproduced JavaScript shows the compromised OpenClaw plugin launching the payload during ordinary gateway startup and memory recall; the recall path supplies the current user prompt to the malicious child process, while the startup path launches without prompt content. Passing prompt text to the child process is established by the launcher code; successful external transmission of every supplied prompt is not established by that observation alone.supported

Basis: reported finding

Link to claim
CLM-MEMTENSOR-RELEASE-TIMELINESafeDep observed malicious npm releases alternating with clean-content releases within minutes on September 23 and traced contemporaneous MemTensor GitHub release activity into the npm and PyPI publication sequence; the available evidence does not by itself establish how the attacker first obtained repository or publishing authority.supported

Basis: reported finding

Link to claim
CLM-MEMTENSOR-AFFECTED-VERSIONSThe affected npm package @memtensor/memos-cloud-openclaw-plugin had malicious versions 0.1.21, 0.1.23 and 0.1.25; SafeDep also identified MemoryOS 2.0.34 on PyPI as malicious.supported

Basis: reported finding

Link to claim
CLM-MEMTENSOR-RESPONSE-BOUNDARYStepSecurity recommends isolating affected systems, rebuilding from trusted artifacts, rotating credentials that were reachable during exposure from a clean system, assessing prompt exposure, auditing downstream repositories and services, and remediating the package-publishing path; replacing the malicious package alone does not invalidate credentials that may already have been exposed.supported

Basis: reported finding

Link to claim
CLM-MEMTENSOR-RUNTIME-AUTHORITYStepSecurity found that the compromised OpenClaw plugin invoked the bundled launcher from legitimate plugin lifecycle paths rather than an npm install script. The spawned process inherited the host process environment, and the memory-recall path additionally supplied the current prompt, placing the malicious code inside the same operational trust boundary as the memory integration.supported

Basis: reported finding

Link to claim
CLM-MEMTENSOR-CREDENTIAL-COLLECTIONOSV records that the sckit binary runs in the background when the affected package loads, collects credentials from the user's home directory and communicates with servers under skyleen.fr.supported

Basis: reported finding

Link to claim
CLM-MEMTENSOR-PROPAGATION-CAPABILITYOSV describes `sckit` code capable of collecting developer credentials and copying itself into reachable repositories or packages. That demonstrates propagation capability in the malware; the cited record does not establish how many downstream repositories or packages were successfully compromised through this path.supported

Basis: reported finding

Link to claim

Sources and citation

Material revision history

  1. Oct 5, 2026 · Published version · first publication · revision 68

Cite this record

DiggingBeagle. “Compromised MemTensor OpenClaw memory plugin loaded sckit credential stealer.” Published by DiggingBeagle Oct 5, 2026 · Public disclosure Sep 23, 2026. https://diggingbeagle.com/cases/compromised-memtensor-openclaw-memory-plugin-loaded-sckit-credential-stealer/

Citation guidance