- Sources: primary, discussion
- Summary: Socket reports credential-stealing code in the npm package
@memtensor/memos-cloud-openclaw-plugin at versions 0.1.21, 0.1.23, and 0.1.25, and in the PyPI package MemoryOS at version 2.0.34. Only 0.1.25 carries the npm latest tag, and 2.0.34 is the current PyPI release, so a default install on either registry resolves to a compromised build. Socket states the payload runs on module import or gateway start rather than on an explicit API call, and names 0.1.20 and 2.0.33 as the last known-good versions to pin to. - Why it matters: A default install pulls a compromised build on both registries, and execution on import or gateway start puts developer machines, CI runners, and containers that only ran tests in scope.
- Follow-up: Track whether clean versions ship above 0.1.25 and 2.0.34, and whether the maintainer account compromise is explained.
send feedback on this story