{"ok":true,"trend":{"id":128294,"platform":"mastodon","region":"global","key":"\"import memos\" alone is enough to start a credential stealer. memoryos 2.0.34 on pypi: 149 modules call get_logger() at","title":"\"import memos\" alone is enough to start a credential stealer. MemoryOS 2.0.34 on PyPI: 149 modules call get_logger() at","url":"https://mastodon.social/@shellonline/117343842133787994","first_seen":"2026-09-27T16:27:42.220086Z","last_seen":"2026-09-27T16:27:42.220086Z","last_rank":3,"peak_rank":3,"last_volume":1,"peak_volume":1,"seen_count":1,"score":18.9375,"category_hint":"cybersecurity","section":"technology","category":"cybersecurity","summary":"Security researchers report that the Python package MemoryOS, version 2.0.34 on PyPI, is trojanized: simply importing the 'memos' module is said to trigger malicious code. Of the package's modules, 149 reportedly call get_logger() at import time, and a modified logger allegedly launches a Go binary, 'sckit', that harvests .npmrc files, Vault tokens, SSH keys and environment secrets. The npm OpenClaw plugin is also named in the report.","why":"Developers are warning about a supply-chain attack on widely used open-source package registries, prompting urgent checks for affected versions.","tone":"negative","entities":["MemoryOS","PyPI","npm","OpenClaw"],"summarized_at":"2026-09-27T16:29:49.410171Z","meta":{"tag":"cybersecurity","via":"scan","kind":"status","lang":"en","generic":0.04,"instance":"mastodon.social","tag_uses":992},"nw":0.38,"promo":0.03,"kind":"news_event","importance":1.8,"hidden":false,"hide_reason":null,"judged_at":"2026-09-27T16:27:42.771020Z","title_en":"PyPI package MemoryOS accused of hiding credential stealer","section_name":"Technology","category_name":"Cybersecurity","timeline":[{"captured_at":"2026-09-27T16:27:42.220086Z","rank":3,"volume":1}],"posts":[{"platform":"mastodon","url":"https://mastodon.social/@shellonline/117343842133787994","author":"shellonline","title":null,"snippet":"\"import memos\" alone is enough to start a credential stealer. MemoryOS 2.0.34 on PyPI: 149 modules call get_logger() at import time, and the modified logger launches a Go binary (sckit) that reads .npmrc, .vault-token, SSH keys and env secrets. The npm OpenClaw plugin…","posted_at":"2026-09-27T16:02:14.914000Z","likes":1}],"elsewhere":[],"window":"7d"}}