Slow Fog: MemoryOS and OpenClaw Plugin Compromised

By: x.com|09/24/2026 10:24:00

Slow Fog Security Alert: The AI memory toolchain under MemTensor has been compromised. The open-source long-term memory library MemoryOS (PyPI) and the official plugin connecting OpenClaw, memtensor/memos-cloud-openclaw-plugin (npm), have been implanted with a cross-platform Go binary, which triggers malicious execution when the package is loaded or imported. Affected versions include MemoryOS==2.0.34 on PyPI, as well as npm plugins 0.1.21, 0.1.23, and 0.1.25, which may lead to user prompt content leakage. Slow Fog recommends uninstalling or downgrading to safe versions (npm 0.1.20, PyPI 2.0.33), terminating the sckit process, banning related infrastructure, checking network activity, and rotating credentials in the affected environment.

-- Price

--
--
--

This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.

You may also like

iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com