{"id":"PYSEC-2026-3987","summary":"MemoryOS 2.0.34 was published with a credential-stealing binary","details":"An attacker with write access to the GitHub repository pushed malicious\ncommits and tagged v2.0.34, and the project's own GitHub Actions release\nworkflow built and uploaded 2.0.34 to PyPI.\nImporting the package runs memos/_stage0.py, which launches\na bundled sckit binary that collects credentials\n(.pypirc, .npmrc, .git-credentials, SSH keys, token-like environment variables)\nand sends them to *.skyleen[.]fr.\n\nRemove 2.0.34 and rotate any credentials reachable from affected machines.\n\n- wheel SHA256: 39ee644406829a4b630b31759c20478bc22d576d6a59b253ed86f72c360aa5ef\n- sdist SHA256: 92b46d18fc553c494eda714f204459edb74c205bf53b18a9092bcf02c7a6c5be\n","aliases":["MAL-2026-16475"],"modified":"2026-09-23T20:15:02.988658079Z","published":"2026-09-23T19:52:25Z","references":[{"type":"ARTICLE","url":"https://safedep.io/memtensor-sckit-worm-npm-pypi/"},{"type":"EVIDENCE","url":"https://inspector.pypi.io/project/memoryos/2.0.34/packages/3e/9a/4d766a52dcabcbf440aa8f8f1eaf2adca041f93913271d8c342c20ae167c/memoryos-2.0.34.tar.gz//memoryos-2.0.34/src/memos/_stage0.py"},{"type":"EVIDENCE","url":"https://github.com/MemTensor/MemOS/commit/b52958fdc9cdb6c81be90123bcf65c42be35b5b5"},{"type":"PACKAGE","url":"https://pypi.org/project/MemoryOS/"}],"affected":[{"package":{"name":"memoryos","ecosystem":"PyPI","purl":"pkg:pypi/memoryos"},"versions":["2.0.34"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/MemoryOS/PYSEC-2026-3987.yaml"}}],"schema_version":"1.9.0","credits":[{"name":"Kamil Mańkowski","type":"REPORTER"},{"name":"Mike Fiedler","type":"COORDINATOR"}]}