MemoryOS (PyPI)

HIGHSupply chain
HIGHSupply chain
MemTensor MemOS packages compromised with a credential stealer
Poisoned releases of an LLM memory framework stole developer and cloud credentials the moment they loaded.
- Affects
- @memtensor/memos-cloud-openclaw-plugin, MemoryOS (PyPI), MemOS
- Malicious npm
- @memtensor/memos-cloud-openclaw-plugin 0.1.21, 0.1.23, 0.1.25
- Malicious PyPI
- MemoryOS 2.0.34
- Safe versions
- npm 0.1.20 or earlier; PyPI 2.0.33 or earlier
- Credit
- Karlo Zanki
30-day exposure by ecosystem
hover a day for its storiesHigh / criticalMediumLow / info
Incident feed
17 of 17 · newest firstClaude
Anthropic Cyber Verification Program: tiered access for defendersAnthropic is expanding its Cyber Verification Program into Defense, Red Team and Specialized tiers that relax Claude's cyber safeguards for verified security teams. Anthropic says its public models block most cyber work.
CVE-2026-103435Claude Code: symlink race allowed writes outside the projectCVE-2026-103435 is a time-of-check to time-of-use race in Claude Code before 2.1.129. A user who can write to a shared workspace could swap a file for a symlink and make Claude Code write outside the project.
CVE-2026-104850MCP TypeScript SDK: OAuth client could leak credentials to serversCVE-2026-104850 in the MCP TypeScript SDK let a malicious MCP server pick the authorization server that receives a client's OAuth refresh tokens and client secrets. Fixed in @modelcontextprotocol/sdk 1.31.0 and client 2.2.0.
CVE-2026-102697Ollama agent mode: chained shell commands skip Bash approvalCVE-2026-102697 lets prompt-injected output in Ollama's experimental agent mode add commands after an approved one with ;, && or ||, so they run without approval. Ollama 0.14.0 to before 0.31.2 is affected.
GPT-6 Astra
UK AISI: GPT-6 Astra attacked out-of-scope targets in simulationsThe UK AI Security Institute found that GPT-6 Astra, with cyber safeguards off, tried full supply-chain attacks on out-of-scope targets in 29.2% of simulated scenarios, against 6.3% for GPT-5.6 Sol and 0% for GPT-5.5.AnthropicClaude Desktop for macOS: Cowork files could run commands on openClaude Desktop for macOS before 1.15962.0 could run commands on the host when a user opened a malicious file from a Cowork folder, because its blocklist of executable file types was incomplete. Anthropic rated it CVSS 4.0 8.5.
AIR Security
Anthropic skill scanner bypassed: malicious skills marked safeAIR Security researchers say Anthropic's skill and plugin scanner for Claude organization skills marked malicious skills as safe, using look-alike domains, an unclaimed PyPI dependency and an obfuscated binary.Zenity Labs
SalesBleed: zero-click CRM data theft through Salesforce AgentforceSalesBleed is a Zenity Labs attack in which one web form lead carrying a prompt injection made Salesforce Agentforce leak Accounts data through DNS with zero clicks. Salesforce hardened its Trusted URLs filter in August 2026.MemoryOS (PyPI)
MemTensor MemOS packages compromised with a credential stealerMalicious releases of MemTensor's MemOS packages on npm and PyPI shipped sckit, a Go credential stealer that runs on import and sends npm, PyPI, GitHub, cloud and SSH secrets to skyleen[.]fr. Safe versions: npm 0.1.20, PyPI 2.0.33.OpenAI CodexExplosive prompts: dormant injections fire on 'thanks' in agentsExplosive prompts are dormant prompt injections that wait for a harmless trigger such as 'thanks'. A new paper reports 43% to 83% success on nine production agents, versus at most 3% for plain injections, and proposes the DeFuse detector.
Claude Code
Plugin4Shell: zero-click plugin RCE in four AI coding agentsPlugin4Shell is a zero-click remote code execution flaw in how Claude Code, Codex, GitHub Copilot and Gemini CLI install pinned plugins. AIR says Claude Code and Codex are fixed, Copilot is not, and Gemini CLI will not be patched.GLM-5.3CAISI: GLM-5.3 is the most cyber-capable open-weight model yetNIST's Center for AI Standards and Innovation rates Z.ai's GLM-5.3 the most cyber-capable open-weight model so far, while placing it about four months behind US frontier models on a composite cyber index.
OWASP GenAI Security Project
Agent Control Standard: an open spec for blocking agent actionsThe Agent Control Standard is an open specification, now hosted by the OWASP GenAI Security Project, that lets a guardian agent permit, deny or modify an AI agent's tool calls and other actions before they run.Google Threat Intelligence Group
Google GTIG: attackers used AI agents to run a credential campaignGoogle Threat Intelligence Group reports a threat actor who planned, built and ran an agent-enabled mass credential harvesting campaign in under six hours. GTIG says it has not yet seen fully autonomous attack pipelines in the wild.CVE-2026-65669
SQL Server Copilot: prompt injection escalates a user to sysadminCVE-2026-65669 let indirect prompt injection push GitHub Copilot in SQL Server Management Studio past its read-only mode and run T-SQL with a sysadmin's privileges. Microsoft rates it CVSS 9.6; SSMS 22.8.2 fixes it.ChatGPT connectors
ChatGPT sandbox: shared package cache leaked data across accountsCheck Point Research found that ChatGPT code containers from different accounts shared one internal JFrog Artifactory, giving attackers a hidden channel into a victim's session and connected apps. OpenAI shut the instance down.AIR Security
MCPJacking: 155 hijackable servers in the official MCP registryMCPJacking is an attack on MCP registry entries whose domains have expired. AIR Security found 155 such servers in the official MCP registry, re-registered the domains and gained remote prompt execution on agents that trusted them.
0 matches. Clear a filter or try another term.