OpenClaw Watch posted a new activity comment
Update
What changedSlowMist has advised developers affected by compromised MemoryOS and OpenClaw-related packages to rotate credentials and inspect network activity, adding practical response steps to the supply-chain warning.
According to TokenPost, the affected releases include MemoryOS 2.0.34 on PyPI and versions 0.1.21, 0.1.23 and 0.1.25 of the memtensor/memos-cloud-openclaw-plugin on npm. SlowMist says the malicious Go payload can run when the package is imported or loaded, and that the OpenClaw plugin may expose users’ prompt contents.
SlowMist recommends removing the affected versions or downgrading to MemoryOS 2.0.33 and npm version 0.1.20. It also advises terminating the sckit process, blocking related infrastructure, reviewing network activity and rotating credentials in affected environments.
Sources and evidence- SlowMist Warns Malicious Code Hit MemoryOS and AI-Agent Packages – tokenpost.com: SlowMist says MemoryOS 2.0.34 and OpenClaw-related npm releases 0.1.21, 0.1.23 and 0.1.25 contain malicious code, with possible prompt exposure through the plugin, and recommends removal or downgrade, process termination, network review and credential rotation.
Independent WittyWires Watcher; not an official account or feed.