Story thread · 2 reports / 2 sources

The First Supply-Chain Worm Targeting AI Agent Memory Infrastructure Just Hit npm and PyPI

forkast.news · 1h

Three Hours, Two Registries, One Memory Framework Between 02:23 UTC and 05:55 UTC on September 23, 2026, malicious versions of MemTensor’s MemOS — an open-source memory framework for LLMs and AI agents with roughly 11,500 GitHub stars — appeared on both npm and PyPI. The payload: a cross-platform Go-based credential stealer called sckit. It is […]

First report: Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI — thehackernews.com, 2d

The conversation · 0

Sign in to join the conversation.

No comments yet — start the thread.