Slow Mist: MemoryOS and OpenClaw plugins were poisoned

Sep 24, 2026 18:25:57

According to Slow Fog Security Alert, the AI memory toolchain under MemTensor has been compromised. The open-source long-term memory library MemoryOS (PyPI) aimed at LLM and AI Agent, as well as the official plugin memtensor/memos-cloud-openclaw-plugin (npm) that connects to the OpenClaw runtime, have been implanted with a cross-platform Go binary, which triggers execution when the package is loaded or imported.

Affected versions include: MemoryOS==2.34 on PyPI, and npm plugins 0.1.21, 0.1.23, 0.1.25. Among them, the affected npm plugins may also cause user prompt content leakage. Slow Fog recommends taking the following measures: uninstall or downgrade to known safe versions (npm 0.1.20, PyPI 2.33); terminate the sckit process; block related infrastructure; check network activity; and rotate credentials in the affected environment.

Recent Fundraising

More
Sep 25
$1.7MSep 24
$37MSep 24

New Tokens

More
Oct 8
Sep 28
AAevaAEVA
Sep 25

Latest Updates on 𝕏

More
Sep 26
Sep 26
SSolanaFollowedPaid
Sep 26