Story · Socket Blog
MemTensor npm and PyPI Packages Compromised in Credential-Stealing Supply Chain Attack (Socket Blog)
blog post · Story page
Socket reports that two MemOS packages, one on npm and one on PyPI, were compromised to drop Go binaries that steal developer secrets.
In plain words
- Two tools that help artificial intelligence remember information were tampered with to steal developers' secrets.
- The affected software, MemoryOS and @memtensor/memos-cloud-openclaw-plugin, installs extra programs that send developers' private information elsewhere.
- Developers using either tool risk exposing secrets across different types of computers.
Appeared in
- Two MemOS packages shipped credential stealers into the agent memory layer
Sep 24, 2026 · lead story
Subscribe
Get the brief in your inbox
Pick daily, weekly, or both. Nothing is gated either way: every issue is on the site and in the feeds.
- Weekdays at 8:45am IST, one lead story and 6 to 9 items.
- Sundays, an argued synthesis rather than a recap.
- One click to leave, and quiet days say so in the subject line.