UNKNOWN PyPI Malware

MemoryOS 2.0.34 was published with a credential-stealing binary

PYSEC-2026-3987 · MAL-2026-16475

Published · Modified

Dependency scanning

Check whether memoryos is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Description

An attacker with write access to the GitHub repository pushed malicious
commits and tagged v2.0.34, and the project's own GitHub Actions release
workflow built and uploaded 2.0.34 to PyPI.
Importing the package runs memos/_stage0.py, which launches
a bundled sckit binary that collects credentials
(.pypirc, .npmrc, .git-credentials, SSH keys, token-like environment variables)
and sends them to *.skyleen[.]fr.

Remove 2.0.34 and rotate any credentials reachable from affected machines.

  • wheel SHA256: 39ee644406829a4b630b31759c20478bc22d576d6a59b253ed86f72c360aa5ef
  • sdist SHA256: 92b46d18fc553c494eda714f204459edb74c205bf53b18a9092bcf02c7a6c5be

Ready to move

Start Securing

Free, no credit card | First findings in minutes