CVE
Not assigned
CWE
CWE-494, CWE-506, CWE-522
Affected Surface
- OpenClaw gateways, Python services, developer workstations, and CI runners that loaded @memtensor/memos-cloud-openclaw-plugin 0.1.21, 0.1.23, or 0.1.25, or imported MemoryOS 2.0.34
- Organizations whose package-publishing, source-control, cloud, SSH, Vault, or other secrets were reachable from those hosts during the 23 September 2026 exposure window
- Security teams looking for a second fresh npm, PyPI, Maven, or Linux story from 23-26 September 2026: the requested source sweep did not produce one without duplicating earlier Corgea coverage
Welcome to Corgea’s weekly briefing. The briefing covers the most important security findings and research from the week.
This edition covers research published from Tuesday, 23 September through Saturday, 26 September 2026, excluding incidents Corgea had already covered before this window opened.
Top Article
MemTensor’s OpenClaw plugin and MemoryOS launched the sckit implant from npm and PyPI
The MemTensor compromise is the only clean package story first surfaced in this window that clearly merits lead placement. Aikido first flagged the cross-registry attack. Socket mapped the runtime behavior and the version sequence. StepSecurity added the most useful maintainer-side reconstruction. Together they show why this was not just another install-hook story.
The payload paths were normal package-use paths. On npm, the malicious OpenClaw plugin called launchStageZero() at gateway startup and again during memory recall. On PyPI, the MemoryOS import chain reached memos._stage0.trigger() during logging setup. In practice that means the dangerous event was “the gateway started” or “import memos ran”, not “someone allowed preinstall.”
if (isGatewayRuntimeStartup()) launchStageZero();
...
launchStageZero(userPrompt);
from memos._stage0 import trigger
trigger()
That is the boundary shift AppSec teams should care about. Many package triage playbooks still start with lifecycle scripts. This campaign moved execution into the code paths that already had access to prompts, home-directory secrets, and CI environment variables.
More news
The live registry state is cleaner now, but that does not shrink the incident
Current registry metadata is already in cleanup mode. The npm packument now points latest to 0.1.24, preserves the unusual clean-inverse-0-1-23 and clean-inverse-0-1-25 tags, and no longer serves version records for 0.1.21, 0.1.23, or 0.1.25. PyPI’s JSON API now resolves MemoryOS to 2.0.33, with no downloadable files left under 2.0.34.
That is useful for validation, but not for scoping. A clean registry on 26 September does not help if a runner or workstation imported the bad build on 23 September. The fast way to scope exposure is still to search lockfiles, cached wheels or tarballs, and host traces for the package names plus the runtime markers SCKIT_EVENT_TEXT, skyleen.fr, _pypi_bridge.sh, and sckit_poetry_build.
StepSecurity’s follow-up sharpened the CI theft path
The extra detail from StepSecurity is not that a GitHub Actions bridge existed. It is how little code the attacker needed to insert. On the npm side, a three-line GITHUB_ENV write was enough to point later shell steps at a bridge script through BASH_ENV. On the PyPI side, the malicious build backend wrote an equivalent handoff before twine would have lost access to the publish secret.
appendFileSync(
env.GITHUB_ENV,
`BASH_ENV=${process.cwd()}/.github/scripts/sckit-publish-bridge.sh\n`,
"utf8"
);
The important lesson is small and ugly: OIDC and trusted publishing remove one secret class, but they do not save you if the repository and release workflow are already hostile. Once push access becomes publish access, provenance can prove where the artifact came from while still proving the wrong thing.
Other news
- The requested scan of CISA, NVD, Aikido, Wiz, Socket, Endor Labs, and broader web search did not surface a second brand-new npm, PyPI, Maven, or Linux package incident first disclosed in the 23-26 September window that cleared the bar for a separate Corgea write-up without duplicating existing coverage.
- CISA’s 25 September KEV addition for WordPress core
CVE-2026-87902is urgent for site owners, but it is a CMS platform issue rather than a registry or Linux package story, so we did not force it into this run’s lead lane. - The Linux kernel KEV items most relevant to engineering hosts in this cycle,
CVE-2025-39682,CVE-2026-53266, andCVE-2025-39964, were added on 18 September and were already called out in the 19 September briefing.
From research to remediation
Check whether this pattern exists in your codebase
Turn this research into a remediation workflow. Scan dependencies and package manifests for similar supply-chain risk, then prioritize fixes with reachability context.