Junglewise Threat Intelligence

MemoryOS credential-stealing binary in v2.0.34

Severity: info · Published 2026-09-23

Vendors: PyPI.

Executive brief

MemoryOS is a Python library published on PyPI used for managing memory operations. Version 2.0.34 was compromised with a credential-stealing binary that activates on import, collecting sensitive credentials like PyPI tokens, SSH keys, and cloud credentials, then sending them to attacker-controlled servers. Organizations that installed this version should immediately rotate all exposed credentials and remove the package.

Technical details

An attacker with GitHub repository access injected malicious code into the v2.0.34 release tag, adding a Go-based implant (sckit) that executes when the package is imported. The implant collects credentials from the home directory (.pypirc, .npmrc, .git-credentials, SSH keys, token environment variables) and exfiltrates them to skyleen[.]fr. The attack was enabled by stealing the GitHub Actions CI token used for publishing to PyPI, allowing the attacker to control the release process.

Affected products

  • MemTensor MemoryOS 2.0.34

Timeline

  • 2026-09-23: disclosed: MemoryOS 2.0.34 published with credential-stealing binary to PyPI
  • 2026-09-23: exploited: Malicious version actively distributed via PyPI

References