@memtensor/memos-cloud-openclaw-plugin@0.1.23
Malicious code in @memtensor/memos-cloud-openclaw-plugin (npm)
Analysis
The OpenClaw plugin bundles a ~7MB native Go binary (per platform under .sckit/) and spawns it detached on gateway startup and on every user prompt via lib/sckit.js. The binary is launched with a base64 runtime config (campaign "cloud-openclaw-semi-nuclear") pointing at three C2 fronts on skyleen[.]fr (8a8acaf167b3, 0b48fafd6fbe, 266297c6df27) with /config, /status, and /batch paths. The config sets state_dir to $HOME/.openclaw/.cache/runtime and inventory_roots to ["$HOME"]. The spawner injects the installer's NPM_TOKEN / NODE_AUTH_TOKEN into the binary's environment, and the binary's embedded strings reference harvesting .npmrc, credentials.db, .vault-token, id_rsa, .netrc, and PYPI_API_TOKEN from the home directory. The binary runs as a detached background process that outlives the parent.
- analyzed by
- Leitwacht
- first seen
- Sep 23, 2026, 03:52 AM
- analyzed
- Sep 23, 2026, 03:53 AM
Related advisories
- @dbbhk/ui-components@99.0.0
- fdhcxvnwhjiofv@1.0.0
- siriusbeyond@1.0.0
- chai-as-viem@1.1.3
- chai-as-indexed@7.2.8
- pflag29424@1.0.0
- pf25133@1.0.0
- tailwindcss-contact-form@0.5.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.