Security· ★★★· bearish·

SlowMist: MemoryOS library and OpenClaw plugin poisoned with malware

  • Affected versions: MemoryOS==2.0.34 on PyPI and npm plugin 0.1.21, 0.1.23, 0.1.25
  • Malicious Go binary triggers on package load or import
  • The npm plugin may leak user prompt contents
  • SlowMist advises downgrading to npm 0.1.20 and PyPI 2.0.33 and rotating credentials
Why it matters: The supply-chain attack on AI tooling shows malicious code increasingly arrives through dependencies rather than the protocol itself.
Source: PANews