Threat Advisory

MemTensor Supply Chain Attack Targets Developer Sensitive Data

Threat: Supply Chain Attacks
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

A supply chain compromise targeting MemTensor's MemOS ecosystem has affected packages distributed through npm and PyPI. The compromised releases of @memtensor/memos-cloud-openclaw-plugin and MemoryOS contain a cross-platform Go-based payload named sckit that is designed to search developer environments for sensitive credentials and transmit collected data to external command-and-control infrastructure.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

A supply chain compromise targeting MemTensor's MemOS ecosystem has affected packages distributed through npm and PyPI. The compromised releases of @memtensor/memos-cloud-openclaw-plugin and MemoryOS contain a cross-platform Go-based payload named sckit that is designed to search developer environments for sensitive credentials and transmit collected data to external command-and-control infrastructure.[emaillocker id="1283"]

The affected npm releases are 0.1.21, 0.1.23, and 0.1.25 while MemoryOS version 2.0.34 is compromised. These packages embed a malicious Go binary named sckit that supports Windows Linux and macOS across x64 and ARM64 architectures. The npm payload executes when the OpenClaw gateway starts and during memory-recall events while the PyPI payload launches when the memos module is imported. The malware searches developer home directories and environment variables for credentials associated with npm PyPI GitHub GitLab AWS HashiCorp Vault SSH and other developer services. It can also collect API keys access tokens private keys session cookies JWTs and database connection strings before exfiltrating the information.

It using the affected packages should immediately identify and remove compromised releases and revert to known-good releases. Exposed credentials and tokens should be rotated and systems should be investigated for sckit execution. Organizations should also review CI/CD environments and developer workstations for signs of credential exposure or unauthorized package publishing activity.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1195.001 Supply Chain Compromise Compromise Software Dependencies and Development Tools
Initial access T1195.002 Supply Chain Compromise Compromise Software Supply Chain
Execution T1204.002 User Execution Malicious File
Persistence T1543.003 Create or Modify System Process Windows Service
Collection T1005 Data from Local System -
Command and control T1071.001 Application Layer Protocol Web Protocols
Exfiltration T1041 Exfiltration Over C2 Channel -

 

REFERENCES:

The following reports contain further technical details:
https://socket.dev/blog/memtensor-compromise

[/emaillocker]
crossmenu