Evidence · DiggingBeagle record
MemTensor npm and PyPI packages hit by a Go worm
SafeDep package and GitHub timeline analysis of the September 23 MemTensor compromise across @memtensor/memos-cloud-openclaw-plugin and MemoryOS, including alternating clean/malicious npm releases and release-pipeline activity.
- Published
- Sep 23, 2026
- Source role
- primary disclosure
Evidence record
SafeDep package and GitHub timeline analysis of the September 23 MemTensor compromise across @memtensor/memos-cloud-openclaw-plugin and MemoryOS, including alternating clean/malicious npm releases and release-pipeline activity.
Claim-level citations (2)
- supportsCompromised MemTensor OpenClaw memory plugin loaded sckit credential stealer: SafeDep observed malicious npm releases alternating with clean-content releases within minutes on September 23 and traced contemporaneous MemTensor GitHub release activity into the npm and PyPI publication sequence; the available evidence does not by itself establish how the attacker first obtained repository or publishing authority.
Timeline; 'Who is affected'; GitHub and package-publication analysis
- supportsCompromised MemTensor OpenClaw memory plugin loaded sckit credential stealer: The affected npm package @memtensor/memos-cloud-openclaw-plugin had malicious versions 0.1.21, 0.1.23 and 0.1.25; SafeDep also identified MemoryOS 2.0.34 on PyPI as malicious.
Who is affected; malicious/clean version table
Cite this record
DiggingBeagle. “MemTensor npm and PyPI packages hit by a Go worm.” Published Sep 23, 2026. https://diggingbeagle.com/sources/memtensor-npm-and-pypi-packages-hit-by-a-go-worm/