MemTensor’s AI memory toolchain has been compromised, with malicious code injected into the MemoryOS PyPI library and the official OpenClaw npm plugin. According to a SlowMist security alert, affected versions include MemoryOS 2.0.34 and npm plugin versions 0.1.21, 0.1.23, and 0.1.25, which execute a cross-platform Go binary upon import and may leak user prompt data.
Users are advised to immediately uninstall or downgrade to safe versions (npm 0.1.20, PyPI 2.0.33), terminate the sckit process, block related infrastructure, inspect network activity, and rotate all credentials in affected environments to mitigate potential damage.
SlowMist Warns of Malware Injection in MemoryOS and OpenClaw AI Packages
Disclaimer: The content provided on Phemex News is for informational purposes only. We do not guarantee the quality, accuracy, or completeness of the information sourced from third-party articles. The content on this page does not constitute financial or investment advice. We strongly encourage you to conduct you own research and consult with a qualified financial advisor before making any investment decisions.
