MemoryOS 2.0.34 was published with a credential-stealing binary
PYSEC-2026-3987 · MAL-2026-16475
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
An attacker with write access to the GitHub repository pushed malicious
commits and tagged v2.0.34, and the project's own GitHub Actions release
workflow built and uploaded 2.0.34 to PyPI.
Importing the package runs memos/_stage0.py, which launches
a bundled sckit binary that collects credentials
(.pypirc, .npmrc, .git-credentials, SSH keys, token-like environment variables)
and sends them to *.skyleen[.]fr.
Remove 2.0.34 and rotate any credentials reachable from affected machines.
- wheel SHA256: 39ee644406829a4b630b31759c20478bc22d576d6a59b253ed86f72c360aa5ef
- sdist SHA256: 92b46d18fc553c494eda714f204459edb74c205bf53b18a9092bcf02c7a6c5be
References
- ARTICLE https://safedep.io/memtensor-sckit-worm-npm-pypi/
- EVIDENCE https://inspector.pypi.io/project/memoryos/2.0.34/packages/3e/9a/4d766a52dcabcbf440aa8f8f1eaf2adca041f93913271d8c342c20ae167c/memoryos-2.0.34.tar.gz//memoryos-2.0.34/src/memos/_stage0.py
- EVIDENCE https://github.com/MemTensor/MemOS/commit/b52958fdc9cdb6c81be90123bcf65c42be35b5b5
- PACKAGE https://pypi.org/project/MemoryOS/
Ready to move
Start Securing
Free, no credit card | First findings in minutes