MemoryOS 2.0.34 was published with a credential-stealing binary
UnratedPublished Sep 23, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| memoryos PyPI | <= 2.0.34 | No fix yet |
Details and references
An attacker with write access to the GitHub repository pushed malicious commits and tagged v2.0.34, and the project's own GitHub Actions release workflow built and uploaded 2.0.34 to PyPI. Importing the package runs memos/_stage0.py, which launches a bundled sckit binary that collects credentials (.pypirc, .npmrc, .git-credentials, SSH keys, token-like environment variables) and sends them to *.skyleen[.]fr. Remove 2.0.34 and rotate any credentials reachable from affected machines. - wheel SHA256: 39ee644406829a4b630b31759c20478bc22d576d6a59b253ed86f72c360aa5ef - sdist SHA256: 92b46d18fc553c494eda714f204459edb74c205bf53b18a9092bcf02c7a6c5be
- Severity from
- no source yet
- Also known as
- MAL-2026-16475
- safedep.io/memtensor-sckit-worm-npm-pypi/
- inspector.pypi.io/project/memoryos/2.0.34/packages/3e/9a/4d766a52dcabcbf440aa8f8f1eaf2adca041f93913271d8c342c20ae167c/memoryos-2.0.34.tar.gz//memoryos-2.0.34/src/memos/_stage0.py
- github.com/MemTensor/MemOS/commit/b52958fdc9cdb6c81be90123bcf65c42be35b5b5
- pypi.org/project/MemoryOS/
More memos advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 23 | Malicious code in memoryos (PyPI) MAL-2026-16475Unratedno fix yet | Unrated | No fix yet |