MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 4 h ago, last 4 h ago, peak #3

PyPI package MemoryOS accused of hiding credential stealer

Original: "import memos" alone is enough to start a credential stealer. MemoryOS 2.0.34 on PyPI: 149 modules call get_logger() at

Security researchers report that the Python package MemoryOS, version 2.0.34 on PyPI, is trojanized: simply importing the 'memos' module is said to trigger malicious code. Of the package's modules, 149 reportedly call get_logger() at import time, and a modified logger allegedly launches a Go binary, 'sckit', that harvests .npmrc files, Vault tokens, SSH keys and environment secrets. The npm OpenClaw plugin is also named in the report.

Why now: Developers are warning about a supply-chain attack on widely used open-source package registries, prompting urgent checks for affected versions.

MemoryOSPyPInpmOpenClaw

Open on mastodon →

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/128294