# Compromised MemTensor packages expose developer credentials

_Published Wednesday, September 23, 2026 at 10:53 AM EDT · Security, AI · Latest · Tier 2 — Notable_

![Compromised MemTensor packages expose developer credentials — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFThFSFsti-2SIka75bNuMKpyJHtOW2ZPrZtcSjbjFQ64GCNn0WtdssYuWlVTbhaLB5cAJ0vu8FgyNmNsDa8g0Ijy-D1zP4FW7ihVfAjk9xWMYDMMdfZPICGyVdjeDwH3-jyKLHOUnjfaXBJIMxGn_3ngeXFsbb4CLnOibRd4fbwXHYpBkMQTcBQAf0edq/s1700-nu-rw-lo-l85-e365/npm-pypi.jpg)

Attackers compromised legitimate MemTensor packages on npm and the Python Package Index to deliver a credential-stealing program called sckit, according to security researchers cited by The Hacker News. The affected releases include three versions of the @memtensor/memos-cloud-openclaw-plugin package and MemoryOS 2.0.34.

The npm payload runs when an agent gateway starts or handles a memory request; the Python payload runs when the module is imported. Researchers say the program collects cloud, source-code and package-publishing credentials and can receive tasks from an external server. The MemoryOS project has been quarantined on PyPI, while the affected npm versions were still available for download when reported.

## Sources

- [The Hacker News](https://thehackernews.com/2026/09/compromised-memtensor-packages-deliver.html)

---
Canonical: https://techandbusiness.org/newswire/FLNNkBxfY1ZYnVft7UZ4F6
Published: 2026-09-23T14:53:20.813Z
Story chronology: 2026-09-23T13:52:46.000Z
Retrieved: 2026-09-23T16:47:30.332Z
Publisher: Tech & Business (techandbusiness.org)
