Attackers published malicious versions of MemTensor’s MemOS, an open-source memory framework for LLM and AI agent applications with roughly 11,500 GitHub stars, to npm (as @memtensor/memos-cloud-openclaw-plugin) and PyPI (as MemoryOS). The compromise began with direct commits to MemTensor’s own GitHub repositories and embedded a Go-based credential stealer that harvested npm, PyPI, GitHub, GitLab, AWS, Hugging Face, HashiCorp Vault, Slack, Stripe, SendGrid, and SSH credentials from any machine that installed the packages. No confirmed downstream propagation had been documented as of disclosure.