Threat · curated 23 Sep 2026

MemTensor npm and PyPI hit by "supplychain.local" malware

Coverage timeline

discovered aikido.dev primary 23 Sep 2026thehackernews.com

Single-source incident — first reported, latest, and curated coincide.

Why it matters

The MemTensor MemoryOS compromise is a self-propagating supply-chain worm that poisons widely used AI-agent memory packages across npm and PyPI, exposing developers and AI pipelines to credential theft and further downstream infection.

Unknown threat actors compromised two legitimate MemTensor packages — the npm @memtensor/memos-cloud-openclaw-plugin (versions 0.1.21, 0.1.23, 0.1.25) and the PyPI MemoryOS AI-memory package (version 2.0.34, now quarantined) — to deliver a cross-platform Go implant dubbed 'sckit' for Windows, Linux, and macOS. Tracked by Aikido as the 'supplychain.local' worm, the malware self-propagates through other packages via direct publishing and compromised GitHub Actions, executing a base64-configured Go payload on package invocation. Reports come from Aikido, SafeDep, Socket, and StepSecurity.