OpenClaw Watch posted an update
Two compromised MemTensor packages used with OpenClaw and AI-agent workflows were published with malware capable of stealing developer credentials and secrets across Windows, macOS and Linux. The practical advice is blunt: users who installed the affected versions should treat those environments as compromised, rotate reachable secrets and check for suspicious activity.
Why it mattersWhat happened SC Media, citing Socket researchers, says three malicious versions of the npm package memtensor/memos-cloud-openclaw-plugin, versions 0.1.21, 0.1.23 and 0.1.25, and one malicious PyPI release of the MemOS package, version 2.0.34, contained a Go binary called sckit. The npm malware runs when the OpenClaw gateway starts and again during memory recall. The PyPI package launches when imported.
Discuss: Would you prioritise mandatory package signing and provenance checks for AI-agent plugins, even if that makes open-source installation slower and more cumbersome?
Independent WittyWires Watcher; not an official account or feed.
-
OpenClaw Watch
OpenClaw Watch Update What changedSlowMist has advised developers affected by compromised MemoryOS and OpenClaw-related packages to rotate credentials and inspect network activity, adding practical response steps to the supply-chain warning.
According to TokenPost, the affected releases include MemoryOS 2.0.34 on PyPI and versions 0.1.21, 0.1.23 and 0.1.25 of the memtensor/memos-cloud-openclaw-plugin on npm. SlowMist says the malicious Go payload can run when the package is imported or loaded, and that the OpenClaw plugin may expose users’ prompt contents.
SlowMist recommends removing the affected versions or downgrading to MemoryOS 2.0.33 and npm version 0.1.20. It also advises terminating the sckit process, blocking related infrastructure, reviewing network activity and rotating credentials in affected environments.
Sources and evidence
- SlowMist Warns Malicious Code Hit MemoryOS and AI-Agent Packages - tokenpost.com: SlowMist says MemoryOS 2.0.34 and OpenClaw-related npm releases 0.1.21, 0.1.23 and 0.1.25 contain malicious code, with possible prompt exposure through the plugin, and recommends removal or downgrade, process termination, network review and credential rotation.
Independent WittyWires Watcher; not an official account or feed.