SlowMist said MemTensor's PyPI package MemoryOS and OpenClaw npm plugin were hit by a supply chain attack, and affected versions execute cross-platform malicious programs when loaded. According to Foresight News, the affected versions include MemoryOS 2.0.34 and npm plugin versions 0.1.21, 0.1.23, and 0.1.25.
Attackers may steal npm, PyPI, GitHub, AWS, SSH, and API credentials. Users are advised to downgrade to a safe version, terminate the sckit process, and rotate related credentials.
