Evidence · DiggingBeagle record
Sckit supply-chain worm hits MemTensor npm and PyPI scopes
StepSecurity reproduction and artifact analysis showing the compromised OpenClaw plugin launches the bundled sckit payload during ordinary gateway and memory-recall paths, passes the host process environment, and passes the current user prompt during recall.
- Published
- Sep 23, 2026
- Source role
- independent technical reproduction
Evidence record
StepSecurity reproduction and artifact analysis showing the compromised OpenClaw plugin launches the bundled sckit payload during ordinary gateway and memory-recall paths, passes the host process environment, and passes the current user prompt during recall.
Claim-level citations (3)
- supportsCompromised MemTensor OpenClaw memory plugin loaded sckit credential stealer: StepSecurity's reproduced JavaScript shows the compromised OpenClaw plugin launching the payload during ordinary gateway startup and memory recall; the recall path supplies the current user prompt to the malicious child process, while the startup path launches without prompt content. Passing prompt text to the child process is established by the launcher code; successful external transmission of every supplied prompt is not established by that observation alone.
OpenClaw plugin launcher analysis; gateway startup and memory-recall code path; `SCKIT_EVENT_TEXT` discussion
- supportsCompromised MemTensor OpenClaw memory plugin loaded sckit credential stealer: StepSecurity recommends isolating affected systems, rebuilding from trusted artifacts, rotating credentials that were reachable during exposure from a clean system, assessing prompt exposure, auditing downstream repositories and services, and remediating the package-publishing path; replacing the malicious package alone does not invalidate credentials that may already have been exposed.
Remediation guidance and incident-response steps
- supportsCompromised MemTensor OpenClaw memory plugin loaded sckit credential stealer: StepSecurity found that the compromised OpenClaw plugin invoked the bundled launcher from legitimate plugin lifecycle paths rather than an npm install script. The spawned process inherited the host process environment, and the memory-recall path additionally supplied the current prompt, placing the malicious code inside the same operational trust boundary as the memory integration.
'Why an AI Memory Plugin Is a Valuable Target'; launcher analysis; 'The Entry Point: Gateway Startup and Memory Recall'
Cite this record
DiggingBeagle. “Sckit supply-chain worm hits MemTensor npm and PyPI scopes.” Published Sep 23, 2026. https://diggingbeagle.com/sources/sckit-supply-chain-worm-hits-memtensor-npm-and-pypi-scopes/