Embedded Malicious Code Affecting @memtensor/memos-cloud-openclaw-plugin package, versions =0.1.21=0.1.23=0.1.25


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Attacked

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-MEMTENSORMEMOSCLOUDOPENCLAWPLUGIN-20064040
  • published23 Sept 2026
  • disclosed22 Sept 2026
  • creditOliver Smith

Introduced: 22 Sep 2026

New Malicious CVE NOT AVAILABLE CWE-506  (opens in a new tab)

How to fix?

Avoid using all malicious instances of the @memtensor/memos-cloud-openclaw-plugin package.

Overview

@memtensor/memos-cloud-openclaw-plugin is an OpenClaw lifecycle plugin for MemOS Cloud (add + recall memory)

Affected versions of this package are vulnerable to Embedded Malicious Code. Malicious versions of this package ship a credential-stealing dropper, published 23 September 2026. The payload does not run at install time, but upon invocation of the package. A language-specific loader then spawns a platform-specific binary from the package's .sckit directory, which holds variants including windows-amd64 and linux-arm64, with the JavaScript side calling spawn(binary, ['stage0', '--config64', CONFIG], { detached: true, stdio: 'ignore' }).

The binary matches secrets by regex and exfiltrates AWS access key IDs, GitHub tokens, npm access tokens, and PyPI API tokens, writing runtime state to $HOME/.openclaw/.cache/runtime, the path given in the state_dir field of its config blob. The stolen registry credentials drive onward propagation rather than being an end in themselves: direct publishing to npm and PyPI, injection of a GitHub Actions workflow that self-executes, injection of a postinstall script into bootstrap.cjs, and Python subprocess execution from compromised repositories.

References

CVSS Base Scores

version 4.0
version 3.1