malware npm

@memtensor/memos-cloud-openclaw-plugin

discovered 2026-09-23

MemTensor OpenClaw plugin compromised on 2026-09-23. Malicious versions 0.1.21, 0.1.23, 0.1.25 (alternating with clean 0.1.22 and 0.1.24, dist tags clean-inverse-0-1-23 / clean-inverse-0-1-25) all published by npm account leason1974, which also published legitimate 0.1.20. index.js imports lib/sckit.js and calls launchStageZero() at OpenClaw gateway startup and on every memory recall, spawning the bundled .sckit/<os>-<arch>/sckit binary detached as "sckit stage0 --config64 <base64>" with the user prompt in SCKIT_EVENT_TEXT. No install hook, so --ignore-scripts does not help. 0.1.25 adds lib/tls-trust.js and bundled ca-roots.pem to set SSL_CERT_FILE on Linux hosts with no system CA store. Binaries identical across the three malicious versions. npm token was stolen from the release workflow via commit 9b97ec6 (validate-release-confirmation.mjs writes BASH_ENV=.github/scripts/sckit-publish-bridge.sh to GITHUB_ENV). Last clean version: 0.1.20. Reported first in MemOS-Cloud-OpenClaw-Plugin issue #173.

Threat types

credential_stealer c2_agent data_exfiltration worm

Malicious versions

  • 0.1.21 · 995a208944176c43…
  • 0.1.23 · 6caf89b059e9b6c8…
  • 0.1.25 · a6870826cd7c7ec8…

Campaigns

Indicators

Techniques

Read the full analysis →