---
id: PYSEC-2026-3987
aliases:
  - MAL-2026-16475
title: MemoryOS 2.0.34 was published with a credential-stealing binary
summary: MemoryOS 2.0.34 was published with a credential-stealing binary
severity: none
vendor: memoryos
product: memoryos
ecosystem: pip
affected:
  - memoryos
published: '2026-09-23'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T20:15:02.988658079Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/PYSEC-2026-3987'
references:
  - url: 'https://safedep.io/memtensor-sckit-worm-npm-pypi/'
  - url: >-
      https://inspector.pypi.io/project/memoryos/2.0.34/packages/3e/9a/4d766a52dcabcbf440aa8f8f1eaf2adca041f93913271d8c342c20ae167c/memoryos-2.0.34.tar.gz//memoryos-2.0.34/src/memos/_stage0.py
  - url: >-
      https://github.com/MemTensor/MemOS/commit/b52958fdc9cdb6c81be90123bcf65c42be35b5b5
  - url: 'https://pypi.org/project/MemoryOS/'
tags:
  - osv
  - pip
ingestedAt: '2026-09-24T07:16:01.859Z'
---

## Overview

An attacker with write access to the GitHub repository pushed malicious
commits and tagged v2.0.34, and the project's own GitHub Actions release
workflow built and uploaded 2.0.34 to PyPI.
Importing the package runs memos/_stage0.py, which launches
a bundled sckit binary that collects credentials
(.pypirc, .npmrc, .git-credentials, SSH keys, token-like environment variables)
and sends them to *.skyleen[.]fr.

Remove 2.0.34 and rotate any credentials reachable from affected machines.

- wheel SHA256: 39ee644406829a4b630b31759c20478bc22d576d6a59b253ed86f72c360aa5ef
- sdist SHA256: 92b46d18fc553c494eda714f204459edb74c205bf53b18a9092bcf02c7a6c5be


## Affected packages

- `memoryos`

## Remediation

Refer to the advisory for the patched release.
