#SlowMist Alert

This time, it wasn’t the exchange that was tampered with—it was an open-source library used to store long-term memory for an AI Agent. SlowMist singled out MemoryOS’s PyPI 2.0.34 and the npm plugins 0.1.21, 0.1.23, and 0.1.25. The malicious code is hidden inside a cross-platform Go binary, and it runs as soon as the package is loaded. The plugin line may also steal users’ prompts.

For developers who have installed this toolchain, what they should do first—not just downgrade—is rotate credentials. Downgrading only blocks the entry point; anything that has already leaked can’t be retrieved.

$UNI $NIL $ARK