MemTensor AI tools hit by supply chain attack
Blockchain security firm SlowMist reported a supply chain attack targeting MemTensor's MemoryOS (PyPI) and OpenClaw (npm) tools. Malicious code embedded in specific versions of these packages automatically executes upon loading, potentially compromising sensitive data including API tokens, SSH keys, and cloud credentials. Users are advised to downgrade to secure versions and rotate all credentials exposed in the affected environments.
Summaries are written by AI from the original article. Not investment advice.