Executive brief
MemoryOS is a Python library published on PyPI used for managing memory operations. Version 2.0.34 was compromised with a credential-stealing binary that activates on import, collecting sensitive credentials like PyPI tokens, SSH keys, and cloud credentials, then sending them to attacker-controlled servers. Organizations that installed this version should immediately rotate all exposed credentials and remove the package.
Technical details
An attacker with GitHub repository access injected malicious code into the v2.0.34 release tag, adding a Go-based implant (sckit) that executes when the package is imported. The implant collects credentials from the home directory (.pypirc, .npmrc, .git-credentials, SSH keys, token environment variables) and exfiltrates them to skyleen[.]fr. The attack was enabled by stealing the GitHub Actions CI token used for publishing to PyPI, allowing the attacker to control the release process.
Affected products
- MemTensor MemoryOS 2.0.34
Timeline
- 2026-09-23: disclosed: MemoryOS 2.0.34 published with credential-stealing binary to PyPI
- 2026-09-23: exploited: Malicious version actively distributed via PyPI