DEV Community

yutianle
yutianle

Posted on

MemTensor: When an AI Memory Plugin Becomes the Credential Collector

MemTensor: When an AI Memory Plugin Becomes the Credential Collector

StepSecurity reported that the open-source AI memory framework MemTensor had its packages poisoned, and Socket, SafeDep and Aikido independently reproduced the finding. The attacker took a GitHub Actions release token, and on 23 September 2026 pushed malicious builds to both npm and PyPI. The poisoned npm package was @memtensor/memos-cloud-openclaw-plugin at versions 0.1.21, 0.1.23 and 0.1.25, and on PyPI the package MemoryOS was replaced at version 2.0.34.

Why the normal path was enough

The payload did not rely on an install hook, which is the technique most dependency scanners look for. It attached itself to code the agent already runs. In the npm package the malicious logic executed when the OpenClaw agent gateway started and again on every memory recall, and it also sent the user's current prompt text out with the request. On the PyPI side the trigger was the hooked logging initialisation, so a simple import memos in project code was enough to start it.
The stealing component, tracked as sckit, collected npm, PyPI, GitHub, GitLab, AWS and Vault tokens and keys from the developer machine and sent them to an external command and control server. It also carried worm-like behaviour: code to repackage itself into other npm packages, other Python packages and GitHub Actions workflows, so a single developer machine could seed further packages.
Two details sharpen the risk. Version 0.1.25 was published as latest, so an unpinned install could pull a malicious build by default. And the poisoned versions were republished within minutes of being removed, which turns cleanup into a race rather than a single action.

Why an AI memory component is a high-value target

An agent has to hold the credentials it acts with, so the machine running a memory framework tends to carry publishing tokens, cloud keys and API credentials for the models it calls. A memory component also sees prompt text, the one class of data that conventional supply-chain attacks rarely touch. The combination means a single poisoned dependency reaches both the deployment pipeline and the conversation content.

Remediation

  1. Pin the npm package to 0.1.20 and the PyPI package to 2.0.33, or remove them, then rebuild from a clean baseline.
  2. Assume credentials on any host that installed an affected version are exposed. Rotate publishing tokens first, then source hosting, cloud accounts, Vault entries and SSH keys.
  3. Block the command and control endpoint at the network layer as a containment measure, while treating it as secondary to rotation.
  4. Review lockfiles, requirements files and software bills of materials for other projects that pulled the same versions, since the worm behaviour made lateral publication possible.
  5. Keep install hooks on the checklist but do not rely on them. This campaign shows that an attacker can choose the agent's own startup path instead.

References

Top comments (0)