MemTensor’s AI memory toolchain has been compromised, with malicious code injected into the MemoryOS PyPI library and the official OpenClaw npm plugin. According to a SlowMist security alert, affected versions include MemoryOS 2.0.34 and npm plugin versions 0.1.21, 0.1.23, and 0.1.25, which execute a cross-platform Go binary upon import and may leak user prompt data. Users are advised to immediately uninstall or downgrade to safe versions (npm 0.1.20, PyPI 2.0.33), terminate the sckit process, block related infrastructure, inspect network activity, and rotate all credentials in affected environments to mitigate potential damage.