Case · DiggingBeagle record
Compromised MemTensor OpenClaw memory plugin loaded sckit credential stealer
On September 23, 2026, malicious releases of the legitimate MemTensor OpenClaw memory plugin and MemoryOS contained the `sckit` Go implant. This was a publisher/package compromise rather than a look-alike extension: normal gateway startup launched the bundled payload with the host environment, and memory recall launched it again with the current user prompt. OSV documents home-directory credential collection and communication with `skyleen.fr`; StepSecurity establishes prompt transfer into the malicious child process but not successful off-host transmission of every prompt. The release sequence alternated malicious and clean versions, so package replacement alone is not a complete incident response: reachable credentials and publishing authority also require treatment.
Assessment profile
Assessment method- Setting
- production
- Exploitation
- observed live
- Evidence
- Grade B
- Remediation
- mitigation available
Basis and provenance
Multiple package analyses agree on the malicious published versions and credential-stealing implant, and StepSecurity reproduces the OpenClaw execution path. Victim execution counts, complete prompt exfiltration and the attacker's initial access route remain unresolved, so impact is left unbanded.
Assessed Oct 5, 2026 using diggingbeagle.assessment/1.
Evidence basis: CLM-MEMTENSOR-AFFECTED-VERSIONS · CLM-MEMTENSOR-CREDENTIAL-COLLECTION · CLM-MEMTENSOR-PROMPT-PATH · CLM-MEMTENSOR-RELEASE-TIMELINE · OSV MAL-2026-16476: malicious code in @memtensor/memos-cloud-openclaw-plugin · MemTensor npm and PyPI packages hit by a Go worm · Sckit supply-chain worm hits MemTensor npm and PyPI scopes
Timeline
- Sep 23, 2026disclosure
Independent package analyses documented the MemTensor compromise
OSV, SafeDep and StepSecurity documented the malicious releases, credential-stealing behavior and OpenClaw execution path.
- Sep 23, 2026release
Malicious OpenClaw plugin version 0.1.21 published
SafeDep's reconstructed npm timeline identifies version 0.1.21 as malicious.
- Sep 23, 2026release
Malicious version 0.1.23 followed a clean 0.1.22 release
SafeDep recorded clean 0.1.22 at 03:45:44 UTC and malicious 0.1.23 minutes later.
- Sep 23, 2026release
Malicious version 0.1.25 followed a clean 0.1.24 release
SafeDep recorded clean 0.1.24 at 04:33:30 UTC and malicious 0.1.25 minutes later.
Claims & evidence
CLM-MEMTENSOR-PROMPT-PATHStepSecurity's reproduced JavaScript shows the compromised OpenClaw plugin launching the payload during ordinary gateway startup and memory recall; the recall path supplies the current user prompt to the malicious child process, while the startup path launches without prompt content. Passing prompt text to the child process is established by the launcher code; successful external transmission of every supplied prompt is not established by that observation alone.supported
Basis: reported finding
- supportsSckit supply-chain worm hits MemTensor npm and PyPI scopesindependent technical reproduction
OpenClaw plugin launcher analysis; gateway startup and memory-recall code path; `SCKIT_EVENT_TEXT` discussion
CLM-MEMTENSOR-RELEASE-TIMELINESafeDep observed malicious npm releases alternating with clean-content releases within minutes on September 23 and traced contemporaneous MemTensor GitHub release activity into the npm and PyPI publication sequence; the available evidence does not by itself establish how the attacker first obtained repository or publishing authority.supported
Basis: reported finding
- supportsMemTensor npm and PyPI packages hit by a Go wormprimary disclosure
Timeline; 'Who is affected'; GitHub and package-publication analysis
CLM-MEMTENSOR-AFFECTED-VERSIONSThe affected npm package @memtensor/memos-cloud-openclaw-plugin had malicious versions 0.1.21, 0.1.23 and 0.1.25; SafeDep also identified MemoryOS 2.0.34 on PyPI as malicious.supported
Basis: reported finding
- supportsOSV MAL-2026-16476: malicious code in @memtensor/memos-cloud-openclaw-pluginsecondary reporting
MAL-2026-16476 Details and Affected versions
- supportsMemTensor npm and PyPI packages hit by a Go wormprimary disclosure
Who is affected; malicious/clean version table
CLM-MEMTENSOR-RESPONSE-BOUNDARYStepSecurity recommends isolating affected systems, rebuilding from trusted artifacts, rotating credentials that were reachable during exposure from a clean system, assessing prompt exposure, auditing downstream repositories and services, and remediating the package-publishing path; replacing the malicious package alone does not invalidate credentials that may already have been exposed.supported
Basis: reported finding
- supportsSckit supply-chain worm hits MemTensor npm and PyPI scopesindependent technical reproduction
Remediation guidance and incident-response steps
CLM-MEMTENSOR-RUNTIME-AUTHORITYStepSecurity found that the compromised OpenClaw plugin invoked the bundled launcher from legitimate plugin lifecycle paths rather than an npm install script. The spawned process inherited the host process environment, and the memory-recall path additionally supplied the current prompt, placing the malicious code inside the same operational trust boundary as the memory integration.supported
Basis: reported finding
- supportsSckit supply-chain worm hits MemTensor npm and PyPI scopesindependent technical reproduction
'Why an AI Memory Plugin Is a Valuable Target'; launcher analysis; 'The Entry Point: Gateway Startup and Memory Recall'
CLM-MEMTENSOR-CREDENTIAL-COLLECTIONOSV records that the sckit binary runs in the background when the affected package loads, collects credentials from the user's home directory and communicates with servers under skyleen.fr.supported
Basis: reported finding
- supportsOSV MAL-2026-16476: malicious code in @memtensor/memos-cloud-openclaw-pluginsecondary reporting
MAL-2026-16476 Details; decoded runtime configuration and IOC sections
CLM-MEMTENSOR-PROPAGATION-CAPABILITYOSV describes `sckit` code capable of collecting developer credentials and copying itself into reachable repositories or packages. That demonstrates propagation capability in the malware; the cited record does not establish how many downstream repositories or packages were successfully compromised through this path.supported
Basis: reported finding
- supportsOSV MAL-2026-16476: malicious code in @memtensor/memos-cloud-openclaw-pluginsecondary reporting
MAL-2026-16476 Details; propagation and credential-targeting behavior
Sources and citation
Material revision history
- Oct 5, 2026 · Published version · first publication · revision 68
Cite this record
DiggingBeagle. “Compromised MemTensor OpenClaw memory plugin loaded sckit credential stealer.” Published by DiggingBeagle Oct 5, 2026 · Public disclosure Sep 23, 2026. https://diggingbeagle.com/cases/compromised-memtensor-openclaw-memory-plugin-loaded-sckit-credential-stealer/