What happened
Threat actors compromised two legitimate MemTensor packages and delivered sckit on both npm and PyPI. Multiple researchers (StepSecurity, SafeDep, Socket, Aikido) documented the campaign on 2026-09-23, amplified through the 09-25/26 window as the first documented supply-chain worm directly targeting agent memory infrastructure. Malicious versions have been yanked; safe versions are 0.1.24 (npm) / 2.0.33 (PyPI).
Why it matters
Agent memory infrastructure sits inside the highest-credential-density process in modern dev/CI environments. Because the payload triggers on memory recall (not install), merely using an affected agent leaks prompts and inherited credentials, and the embedded self-propagation routines threaten the broader npm/PyPI/GitHub ecosystem. Pin to clean versions, rotate all credentials reachable from affected hosts, and block skyleen[.]fr.
Attack vector
Malicious npm/PyPI releases (published 2026-09-23 via compromised maintainer publish tokens) bundle a cross-platform Go executable (sckit) launched through legitimate plugin code paths (lib/sckit.js on npm; memos/log.py import-time hook on PyPI) — no install scripts, evading standard scanning. It harvests npm/PyPI/GitHub/GitLab tokens, AWS keys, Hugging Face/Vault/Slack/Stripe/SendGrid keys, SSH keys, JWTs and secret-shaped env vars, exfiltrating to skyleen[.]fr; embedded functions (recursivePublish, prepareRemote*) enable worm-like self-propagation through package registries.
Mitigation
Pin @memtensor/memos-cloud-openclaw-plugin to 0.1.24 (or 0.1.20 baseline) and MemoryOS to 2.0.33; remove the packages; rotate registry/source-control/cloud/Vault/SSH credentials; kill any 'sckit' process; block skyleen[.]fr and subdomains.