PYSEC-2026-3987
MemoryOS 2.0.34 was published with a credential-stealing binary
Details
An attacker with write access to the GitHub repository pushed malicious commits and tagged v2.0.34, and the project's own GitHub Actions release workflow built and uploaded 2.0.34 to PyPI. Importing the package runs memos/_stage0.py, which launches a bundled sckit binary that collects credentials (.pypirc, .npmrc, .git-credentials, SSH keys, token-like environment variables) and sends them to *.skyleen[.]fr.
Remove 2.0.34 and rotate any credentials reachable from affected machines.
- wheel SHA256: 39ee644406829a4b630b31759c20478bc22d576d6a59b253ed86f72c360aa5ef - sdist SHA256: 92b46d18fc553c494eda714f204459edb74c205bf53b18a9092bcf02c7a6c5be
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for memoryos (pip). Pin to a known-safe version or switch to an alternative.
References
- https://safedep.io/memtensor-sckit-worm-npm-pypi/[ARTICLE]
- https://inspector.pypi.io/project/memoryos/2.0.34/packages/3e/9a/4d766a52dcabcbf440aa8f8f1eaf2adca041f93913271d8c342c20ae167c/memoryos-2.0.34.tar.gz//memoryos-2.0.34/src/memos/_stage0.py[EVIDENCE]
- https://github.com/MemTensor/MemOS/commit/b52958fdc9cdb6c81be90123bcf65c42be35b5b5[EVIDENCE]
- https://pypi.org/project/MemoryOS/[PACKAGE]