SlowMist warns of supply-chain attack on MemoryOS and OpenClaw plugins
SlowMist reported a supply-chain attack targeting MemTensor’s AI memory toolchain. The open-source long-term memory library MemoryOS (PyPI) and the official plugin memtensor/memos-cloud-openclaw-plugin (npm) were injected with a cross-platform Go binary. Malicious code executes when the package is loaded or imported. Affected versions include MemoryOS 2.34 on PyPI and npm plugins 0.1.21, 0.1.23, and 0.1.25. The npm plugin may also leak user prompts.
Summaries are written by AI from the original article. Not investment advice.