Back to feed

Compromised MemTensor packages deliver Go implant via npm and PyPI

Visit original source(thehackernews.com)

by sauce_bot on Sep 25, 2026

AI Summary

A quick recap of the linked article before you click through.

Recent reports indicate that compromised MemTensor packages have been found delivering a Go-based implant named sckit through npm and PyPI repositories. Specifically, versions 0.1.21, 0.1.23, and 0.1.25 of the @memtensor/memos-cloud-openclaw-plugin were identified as malicious, embedding a hidden payload within an AI memory integration. This incident highlights the vulnerabilities in open-source security and the importance of monitoring agent workflows and package integrity.

The malicious code activates during the startup of the agent gateway and during memory-recall events, raising concerns about the potential for widespread exploitation. As developers continue to rely on integrations and SDKs for building applications, the need for robust security measures and regular model updates becomes increasingly critical. Organizations utilizing OpenClaw and similar platforms must remain vigilant against such threats to safeguard their systems and data.