search
npm
Trends
- 1PyPI package MemoryOS accused of hiding credential stealer●"import memos" alone is enough to start a credential stealer. MemoryOS 2.0.34 on PyPI: 149 modules call get_logger() at
Security researchers report that the Python package MemoryOS, version 2.0.34 on PyPI, is trojanized: simply importing the 'memos' module is said to trigger malicious code. Of the package's modules, 149 reportedly call get_logger() at import time, and a modified logger allegedly launches a Go binary, 'sckit', that harvests .npmrc files, Vault tokens, SSH keys and environment secrets. The npm OpenClaw plugin is also named in the report.
Repos
- Parcha-ai/agentrun The Agentrun Workflow DSL
- tamaratran/fast-jev-compaction Claude Code plugin that replaces the compaction summary with Jev decisions: every tool call and result is scored in one
- nilbuild/page-mascot A mascot that watches the cursor and blinks when you poke it
- vercel-labs/scriptc TypeScript-to-Native Compiler
- WordPress/wordpress-develop WordPress Develop, Git-ified. Synced from git://develop.git.wordpress.org/, including branches and tags! This repository