VDB
Sign up

PYSEC-2026-3987

MemoryOS 2.0.34 was published with a credential-stealing binary

Details

An attacker with write access to the GitHub repository pushed malicious commits and tagged v2.0.34, and the project's own GitHub Actions release workflow built and uploaded 2.0.34 to PyPI. Importing the package runs memos/_stage0.py, which launches a bundled sckit binary that collects credentials (.pypirc, .npmrc, .git-credentials, SSH keys, token-like environment variables) and sends them to *.skyleen[.]fr.

Remove 2.0.34 and rotate any credentials reachable from affected machines.

- wheel SHA256: 39ee644406829a4b630b31759c20478bc22d576d6a59b253ed86f72c360aa5ef - sdist SHA256: 92b46d18fc553c494eda714f204459edb74c205bf53b18a9092bcf02c7a6c5be

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/memoryos

No fixed version published yet for memoryos (pip). Pin to a known-safe version or switch to an alternative.

References