PYSEC-2026-3987None▾ SunlitMemoryOS 2.0.34 was published with a credential-stealing binary
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
An attacker with write access to the GitHub repository pushed malicious commits and tagged v2.0.34, and the project's own GitHub Actions release workflow built and uploaded 2.0.34 to PyPI. Importing the package runs memos/_stage0.py, which launches a bundled sckit binary that collects credentials (.pypirc, .npmrc, .git-credentials, SSH keys, token-like environment variables) and sends them to *.skyleen[.]fr.
Remove 2.0.34 and rotate any credentials reachable from affected machines.
memoryosRefer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.