malware pypi

MemoryOS

discovered 2026-09-23

MemTensor MemOS Python library compromised on 2026-09-23. MemoryOS 2.0.34 was built and uploaded by MemTensor's own release workflow from tag v2.0.34 on unsigned, non-main commits b52958f (author "MemTensor CI Review <[email protected]>", adds six sckit binaries, loader, and in-tree Poetry backend sckit_poetry_build.py) and 41bf5c7 (removes the register() token-capture call). memos/log.py configure_logging() imports memos._stage0.trigger(), which spawns the sckit binary detached with SCKIT_EVENT_TEXT. Wheel grew from 951 KB (2.0.33) to 19 MB. Wheel SHA-256 in versions[]; sdist memoryos-2.0.34.tar.gz SHA-256 92b46d18fc553c494eda714f204459edb74c205bf53b18a9092bcf02c7a6c5be. Last clean version: 2.0.33.

Threat types

credential_stealer c2_agent data_exfiltration worm

Malicious versions

  • 2.0.34 · 39ee644406829a4b…

Campaigns

Indicators

Techniques

Read the full analysis →