Compromised releases of the AI memory-integration package @memtensor/memos-cloud-openclaw-plugin on npm and MemoryOS on PyPI distributed the multiplatform Go-based Sckit worm, also tracked as supplychain.local. Affected npm versions include 0.1.21, 0.1.23, and 0.1.25; the PyPI package was affected from version 2.0.34. The payload executes when affected functionality is invoked—including agent-gateway startup and memory-recall events—rather than during installation, launching detached Windows, Linux, or macOS binaries across x86 and ARM systems. It inherits the host environment and can receive recalled prompts in SCKIT_EVENT_TEXT, potentially exposing credentials and sensitive prompt data available to the process.
The malware is designed to inventory user home directories and steal credentials for cloud providers, source-control services, package registries, AI platforms, and business applications. Its suspected objectives include compromising GitHub repositories and CI environments, planting self-executing GitHub Actions or package hooks, and republishing through npm and PyPI; however, investigators had not confirmed successful exfiltration, propagation, persistence, or public repositories containing its propagation stubs. The rapid alternation of malicious and clean npm releases indicates that the publisher account and release environment may have been compromised. Suspected command-and-control infrastructure includes skyleen.fr domains resolving to 139.84.223.178; version 0.1.25 also added a Linux CA-certificate fallback, likely to improve outbound HTTPS connectivity.

Trace attribution and downstream blast radius.
6 events from the most recent confirmed update back to the earliest known activity.
Malicious npm version 0.1.25 was published three minutes and 28 seconds after clean 0.1.24. It retained the same Sckit payload binaries while adding Linux CA-bundle fallback code, likely intended to improve HTTPS connectivity where system trust bundles were unavailable.
A clean version 0.1.24 was released before a further malicious version was published minutes later, reinforcing evidence of unauthorized or otherwise anomalous package publishing activity.
Malicious npm version 0.1.23 was published three minutes and 36 seconds after clean version 0.1.22, using bundled Sckit executables matching those in the other malicious releases.
A clean version 0.1.22 release was published after malicious 0.1.21, beginning an alternating pattern of clean and malicious registry releases. The examined source repository had no corresponding commits or tags for the malicious artifacts.
A threat actor published malicious @memtensor/memos-cloud-openclaw-plugin version 0.1.21 and reportedly compromised the MemoryOS PyPI package from version 2.0.34. The bundled multiplatform Sckit/Go payload executes when affected packages are invoked rather than during installation.
Version 0.1.20 of @memtensor/memos-cloud-openclaw-plugin was published as the clean comparison baseline, before the malicious releases that followed.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 16 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.