Urgent.News

What's breaking now, across thousands of outlets.

Tech

MemTensor: When an AI Memory Plugin Becomes the Credential Collector

MemTensor: When an AI Memory Plugin Becomes the Credential Collector StepSecurity reported that the open-source AI memory framework MemTensor had its packages poisoned, and Socket, SafeDep and Aikido independently reproduced the finding. The attacker took a GitHub Actions release token, and on 23 September 2026 pushed malicious builds to both npm and PyPI. The poisoned npm package was…

StepSecurity revealed that the open-source AI memory framework MemTensor had its packages compromised, with Socket, SafeDep and Aikido independently confirming the discovery. The intruder exploited a GitHub Actions release token, uploading tainted builds to both npm and PyPI on September 23, 2026. The malicious npm package, @memtensor/memos-cloud-openclaw-plugin, versions 0.1.21, 0.1.23, and 0.1.25, replaced the legitimate package on PyPI as MemoryOS version 2.0.34.

The attack did not exploit an install hook, instead injecting itself into the code already running. In the npm package, the malicious code activated during the OpenClaw agent gateway startup and each memory recall, sending the user's current prompt text with each request. On PyPI, the trigger was the manipulated logging initialization, with a simple "import memos" in project code initiating the theft.

The malicious component, categorized as sckit, harvested npm, PyPI, GitHub, GitLab, AWS, and Vault tokens and keys from the developer's machine and transmitted them to an external command and control server. It also exhibited worm-like capabilities, reformatting itself into other npm packages, Python packages, and GitHub Actions workflows, enabling a single compromised developer machine to disseminate further contaminated software.

Two factors intensified the severity. The tainted version 0.1.25 was designated as the latest release, causing an unpinned installation to default to the malicious build. The poisoned versions were reconveyed within minutes of removal, transforming remediation into a continuous struggle rather than a straightforward process. Notably, an AI memory component is an attractive target as it accesses credentials used by the agent, including publishing tokens, cloud keys, and API credentials for the models it interacts with.

The combination of credentials and sensitive conversation data makes a poisoned dependency a dual threat to the deployment pipeline and the conversational context. To mitigate the risk, developers should lock the npm package to 0.1.20 and the PyPI package to 2.0.33, or eliminate them entirely and rebuild from a clean slate. It is assumed that any credentials on a host that installed a compromised version are exposed, necessitating immediate rotation of publishing tokens, source hosting credentials, cloud accounts, Vault entries, and SSH keys.

Blocking the command and control endpoint at the network level serves as a containment measure, although it is secondary to credential rotation. Reviewing lockfiles, requirements files, and software bills of materials for other projects that incorporated the same versions is recommended, as the worm-like behavior facilitated lateral dissemination.

This incident underscores that an attacker can exploit an agent's startup path, highlighting the importance of vigilance beyond conventional supply-chain defense strategies.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Sobrevivendo ao Inevitável: Engenharia do Caos na Prática com o ChaosEngineeringMasterDeck

Se você trabalha com arquiteturas modernas em nuvem e microsserviços, provavelmente já se deparou com a clássica citação de Werner Vogels, CTO da Amazon: "Failures are a given and everything will…

  • Modern cloud architectures face increasing complexity with interconnected microservices.
  • Chaos Engineering tests systems to build resilience against unexpected production issues.

Cheat Sheet for Your First Open Source Contribution

Making your first open source contribution is intimidating. Honestly, it’s rarely the code that holds people back—it’s usually the fear of messing up a Git command, doing something wrong in the GitHub…

  • GitHub user interface workflow guides where to click to fork and initiate PR
  • Copy-paste VS Code commands for cloning, branching, committing, pushing
  • Formatting tips for commit messages and PR descriptions to boost review chances

💅 Keyboard Makeover

I have had this interesting piece of psychedelic looking vinyl for some time. Today I finally found a use case for it. I turned a regular keyboard into a way more fun and exciting one.

More from Sunday 11 October →