ON 23 September 2026, malicious releases of the npm package `@memtensor/memos-cloud-openclaw-plugin` were found to contain a hidden Go payload. Versions `0.1.21`, `0.1.23` and `0.1.25` launch bundled executables when the OpenClaw agent gateway starts and when the plugin processes a memory-recall event. The launcher runs the child process in the background, passes it the host environment and, during recall, the user’s prompt text. Six executables support Linux, macOS and Windows on AMD64 and ARM64 systems.
Analysis by StepSecurity found credential-matching patterns covering AWS, GitHub, GitLab, npm, PyPI, Hugging Face, Vault, Slack, Stripe and SendGrid, as well as passwords, private keys, API keys, cookies and database connection strings. The embedded configuration sets the user’s home directory as a collection root and names three external endpoints. However, the investigation did not establish successful data theft, the payload’s full behaviour, or successful propagation to PyPI or GitHub. Reports involving `MemoryOS==2.0.34` on PyPI were not independently validated.
The package history alternated between malicious and apparently clean releases: `0.1.22` and `0.1.24` restored clean contents before the payload returned minutes later. The repository’s incident report described malicious npm artefacts without matching source commits, supporting a suspected publishing-path compromise, but not identifying how access was obtained.
Organisations that ran an affected version should isolate hosts and runners, preserve evidence, rebuild from trusted sources, revoke credentials accessible to the process or home directory, review prompt exposure, investigate the listed infrastructure and audit package, repository and workflow activity.