{
  "id": 13616542,
  "title": "MemTensor: When an AI Memory Plugin Becomes the Credential Collector",
  "url": "https://urgent.news/2026/10/11/memtensor-when-an-ai-memory-plugin-becomes-the-credential-collector",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-11T02:21:11.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/bianliang/memtensor-when-an-ai-memory-plugin-becomes-the-credential-collector-4j05"
  },
  "original_language": "en",
  "account": "StepSecurity revealed that the open-source AI memory framework MemTensor had its packages compromised, with Socket, SafeDep and Aikido independently confirming the discovery. The intruder exploited a GitHub Actions release token, uploading tainted builds to both npm and PyPI on September 23, 2026. The malicious npm package, @memtensor/memos-cloud-openclaw-plugin, versions 0.1.21, 0.1.23, and 0.1.25, replaced the legitimate package on PyPI as MemoryOS version 2.0.34. The attack did not exploit an install hook, instead injecting itself into the code already running. In the npm package, the malicious code activated during the OpenClaw agent gateway startup and each memory recall, sending the user's current prompt text with each request. On PyPI, the trigger was the manipulated logging initialization, with a simple \"import memos\" in project code initiating the theft. The malicious component, categorized as sckit, harvested npm, PyPI, GitHub, GitLab, AWS, and Vault tokens and keys from the developer's machine and transmitted them to an external command and control server. It also exhibited worm-like capabilities, reformatting itself into other npm packages, Python packages, and GitHub Actions workflows, enabling a single compromised developer machine to disseminate further contaminated software. Two factors intensified the severity. The tainted version 0.1.25 was designated as the latest release, causing an unpinned installation to default to the malicious build. The poisoned versions were reconveyed within minutes of removal, transforming remediation into a continuous struggle rather than a straightforward process. Notably, an AI memory component is an attractive target as it accesses credentials used by the agent, including publishing tokens, cloud keys, and API credentials for the models it interacts with. The combination of credentials and sensitive conversation data makes a poisoned dependency a dual threat to the deployment pipeline and the conversational context. To mitigate the risk, developers should lock the npm package to 0.1.20 and the PyPI package to 2.0.33, or eliminate them entirely and rebuild from a clean slate. It is assumed that any credentials on a host that installed a compromised version are exposed, necessitating immediate rotation of publishing tokens, source hosting credentials, cloud accounts, Vault entries, and SSH keys. Blocking the command and control endpoint at the network level serves as a containment measure, although it is secondary to credential rotation. Reviewing lockfiles, requirements files, and software bills of materials for other projects that incorporated the same versions is recommended, as the worm-like behavior facilitated lateral dissemination. This incident underscores that an attacker can exploit an agent's startup path, highlighting the importance of vigilance beyond conventional supply-chain defense strategies.",
  "summary": "MemTensor: When an AI Memory Plugin Becomes the Credential Collector StepSecurity reported that the open-source AI memory framework MemTensor had its packages poisoned, and Socket, SafeDep and Aikido independently reproduced the finding. The attacker took a GitHub Actions release token, and on 23 September 2026 pushed malicious builds to both npm and PyPI. The poisoned npm package was…",
  "key_points": [
    "MemTensor's packages compromised by attacker exploiting GitHub Actions token",
    "Malicious npm package replaced legitimate version on PyPI, harvested credentials",
    "Worm-like behavior enabled lateral dissemination, emphasizing need for credential rotation"
  ],
  "editors_take": "This incident highlights the vulnerability of AI memory components as attractive targets for attackers to harvest credentials and sensitive data, necessitating a reevaluation of supply-chain defense strategies.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}