Evidence · DiggingBeagle record

MemTensor npm and PyPI packages hit by a Go worm

SafeDep package and GitHub timeline analysis of the September 23 MemTensor compromise across @memtensor/memos-cloud-openclaw-plugin and MemoryOS, including alternating clean/malicious npm releases and release-pipeline activity.

Published
Sep 23, 2026
Source role
primary disclosure

Cite this record

DiggingBeagle. “MemTensor npm and PyPI packages hit by a Go worm.” Published Sep 23, 2026. https://diggingbeagle.com/sources/memtensor-npm-and-pypi-packages-hit-by-a-go-worm/

Citation guidance