@memtensor/memos-cloud-openclaw-plugin
discovered 2026-09-23MemTensor OpenClaw plugin compromised on 2026-09-23. Malicious versions 0.1.21, 0.1.23, 0.1.25 (alternating with clean 0.1.22 and 0.1.24, dist tags clean-inverse-0-1-23 / clean-inverse-0-1-25) all published by npm account leason1974, which also published legitimate 0.1.20. index.js imports lib/sckit.js and calls launchStageZero() at OpenClaw gateway startup and on every memory recall, spawning the bundled .sckit/<os>-<arch>/sckit binary detached as "sckit stage0 --config64 <base64>" with the user prompt in SCKIT_EVENT_TEXT. No install hook, so --ignore-scripts does not help. 0.1.25 adds lib/tls-trust.js and bundled ca-roots.pem to set SSL_CERT_FILE on Linux hosts with no system CA store. Binaries identical across the three malicious versions. npm token was stolen from the release workflow via commit 9b97ec6 (validate-release-confirmation.mjs writes BASH_ENV=.github/scripts/sckit-publish-bridge.sh to GITHUB_ENV). Last clean version: 0.1.20. Reported first in MemOS-Cloud-OpenClaw-Plugin issue #173.
Threat types
Malicious versions
- 0.1.21 · 995a208944176c43…
- 0.1.23 · 6caf89b059e9b6c8…
- 0.1.25 · a6870826cd7c7ec8…
Campaigns
Indicators
- domain 8a8acaf167b3.skyleen.frcommunicates-with
- domain 0b48fafd6fbe.skyleen.frcommunicates-with
- domain 266297c6df27.skyleen.frcommunicates-with
- file_path $HOME/.openclaw/.cache/runtimeindicates
- file_path lib/sckit.jsindicates
- file_path .github/scripts/sckit-publish-bridge.shindicates
- sha256 381ac6dc1715d9298fe81b2a53a11f7b7d78e361ee3a6619ad54f8c4b062cc18drops
- sha256 e077c387b223811064b7bbc5a55a0182fca9bf50894f949ff284d4be87d44b26drops
- sha256 65faf8ccbcf5b34eb4f72c71bf82815fa9c1e2f947b9c898491540e866132c31drops
- sha256 f8ccdd1da7dff1aef16377a2842bc7acf7c516e32122dd6e42dc4a4e57653fcedrops
- sha256 56cd3416d2ec2aa7e7cec2a06010cf0b58eb09c0a5486809df52afeaca8f14bedrops
- sha256 d6b3e77c36ee8017c9bf30d1da7218ec0ea843768d313eb8e35845c8a9b38a26drops
Techniques
- ttp T1195.002 Compromise Software Supply Chainuses
- ttp T1528 Steal Application Access Tokenuses
- ttp GITHUB_ENV BASH_ENV Injectionuses
- ttp T1059.004 Unix Shelluses
- ttp T1059.007 JavaScriptuses
- ttp T1480 Execution Guardrailsuses
- ttp T1070.004 File Deletionuses
- ttp T1071.001 Web Protocolsuses
- ttp T1552.001 Credentials In Filesuses
- ttp T1082 System Information Discoveryuses
- ttp T1614 System Location Discoveryuses
- ttp T1573 Encrypted Channeluses
- ttp T1041 Exfiltration Over C2 Channeluses