{"id":1953,"date":"2026-09-24T12:44:50","date_gmt":"2026-09-24T07:14:50","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1953"},"modified":"2026-09-28T11:48:04","modified_gmt":"2026-09-28T06:18:04","slug":"ai-memory-packages-become-credential-stealing-supply-chain-implants","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/ai-memory-packages-become-credential-stealing-supply-chain-implants\/","title":{"rendered":"AI Memory Packages Become Credential-Stealing Supply-Chain Implants"},"content":{"rendered":"<p>The MemTensor compromise turned legitimate AI memory packages into a credential-theft channel. Malicious releases on npm and PyPI delivered sckit, a Go-based stealer targeting Windows, Linux, and macOS. For security administrators, the exposure spans developer workstations, agent gateways, and automation environments.<\/p>\n<p>These integrations can run with access to prompts, repositories, and credentials. That makes package execution an enterprise security concern, particularly when developers reuse privileged accounts across tools.<\/p>\n<h2>How the MemTensor compromise reaches developer environments<\/h2>\n<p>Researchers identified malicious releases of two packages:<\/p>\n<table>\n<thead>\n<tr>\n<th>Package<\/th>\n<th>Affected versions<\/th>\n<th>Additional findings<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><code>@memtensor\/memos-cloud-openclaw-plugin<\/code> on npm<\/td>\n<td>0.1.21, 0.1.23, 0.1.25<\/td>\n<td>Researchers reported 0.1.22 and 0.1.24 clean.<\/td>\n<\/tr>\n<tr>\n<td><code>MemoryOS<\/code> on PyPI<\/td>\n<td>2.0.34<\/td>\n<td>PyPI quarantined the project.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The September 23 reporting identifies the affected releases and quarantine status. Teams should check resolved dependency versions rather than assuming every release within the same range is malicious.<\/p>\n<p>The npm plugin launches its hidden payload when the agent gateway starts and during memory-recall events, passing the user\u2019s prompt and environment data to the executable. Meanwhile, the Python package triggers execution when the application configures logging via <code>memos.log.configure_logging().<\/code><\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-2.webp?format=webp\" class=\"resource-box__image\" alt=\"cybersecurity-kit\" loading=\"lazy\" srcset=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-2.webp?format=webp 960w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-2-300x225.webp?format=webp 300w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-2-768x576.webp?format=webp 768w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-2-133x100.webp?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"cybersecurity-kit\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured Resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Cybersecurity kit\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Access essential cybersecurity resources to strengthen security, reduce risk, and improve cyber resilience.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/resource-kits\/cybersecurity-kit\/'>\n                            Download the Resource Kit\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h2>What the MemTensor compromise exposes<\/h2>\n<p>The stealer targets credential files and environment variables containing cloud keys, registry tokens, and other secrets. Targets include AWS credentials, GitHub and GitLab tokens, npm and PyPI publishing tokens, Vault tokens, SSH keys, Hugging Face tokens, and JSON Web Tokens (JWTs). Researchers identified skyleen[.]fr as exfiltration infrastructure.<\/p>\n<p>SafeDep traced publishing-token theft to MemTensor\u2019s GitHub Actions release pipelines. Its analysis also found templates for spreading through npm packages, Python packages, and GitHub Actions workflows. These findings indicate propagation capability; they do not establish the full extent of infections beyond MemTensor.<\/p>\n<p>For enterprises, this creates a second exposure path: stolen publishing credentials could put downstream consumers at risk.<\/p>\n<h2>What security teams should do now<\/h2>\n<p>Start with package exposure, then expand the investigation to every identity available during execution.<\/p>\n<ol>\n<li><strong>Locate affected installations.<\/strong> Review lockfiles, build records, developer environments, agent gateways, and CI images. Record package versions, execution times, and responsible owners.<\/li>\n<li><strong>Contain suspicious execution.<\/strong> Investigate sckit processes and connections to the reported domain. Preserve process details, relevant logs, and payload hashes before cleanup.<\/li>\n<li><strong>Revoke and rotate exposed secrets.<\/strong> Include credentials injected into jobs and secrets accessible through local files. Perform rotation from a trusted environment.<\/li>\n<li><strong>Restore a verified dependency baseline.<\/strong> Remove malicious releases and rebuild affected environments from trusted inputs. Check caches and reusable images before restarting jobs.<\/li>\n<li><strong>Audit downstream activity.<\/strong> Review repository changes, workflow modifications, package publications, and cloud activity associated with exposed identities.<\/li>\n<\/ol>\n<p>Treat these as coordinated response steps. A dependency rollback alone cannot revoke a stolen token or undo unauthorized publications. Assign endpoint, cloud, and development owners to the same investigation so cleanup and credential recovery proceed together.<\/p>\n<h2>How Hexnode supports endpoint investigation and containment<\/h2>\n<p>Hexnode can support the endpoint portion of this response on supported, enrolled devices.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/uem\/\">Hexnode UEM<\/a> compliance policies help administrators assess devices against configured requirements and identify posture gaps for follow-up. Compliance status should inform endpoint hygiene decisions; it does not certify that an npm or Python dependency is safe.<\/p>\n<p>While sckit targets Windows, macOS, and Linux, <a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a>\u2019s Visual Process Tree and one-click remediation actions operate on Windows and macOS endpoints. Administrators can investigate process relationships and initiate Isolate Device, Kill Process \/ Kill Process Tree, and Quarantine File actions. Linux endpoints are managed through Hexnode UEM policy actions.<\/p>\n<table>\n<thead>\n<tr>\n<th>Response objective<\/th>\n<th>Hexnode XDR action<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Restrict an affected endpoint\u2019s connectivity<\/td>\n<td>Isolate Device cuts network access while maintaining the endpoint\u2019s connection to the Hexnode console for ongoing forensic investigation.<\/td>\n<\/tr>\n<tr>\n<td>Stop malicious processes<\/td>\n<td>Kill Process \/ Kill Process Tree terminates a selected process or its process tree, respectively.<\/td>\n<\/tr>\n<tr>\n<td>Contain a malicious payload<\/td>\n<td>Quarantine File blocks and encrypts the file for review.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>These administrator-initiated actions support containment. Credential revocation, package verification, and CI recovery still require coordination with the teams operating those systems.<\/p>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">How can organizations tell whether they installed a malicious MemTensor package?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Teams should check resolved dependency versions in lockfiles, build records, developer environments, agent gateways and CI images. The reported malicious releases include @memtensor\/memos-cloud-openclaw-plugin versions 0.1.21, 0.1.23 and 0.1.25, plus MemoryOS version 2.0.34.<\/p>\n<\/div><\/div><\/div> <div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">What credentials can the sckit malware steal?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>sckit targets credential files and environment variables containing secrets such as AWS credentials, GitHub and GitLab tokens, npm and PyPI publishing tokens, Vault tokens and SSH keys. Security teams should assess which credentials were accessible wherever an affected package executed.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n<h3>Protect the secrets behind AI integrations<\/h3>\n<p>AI integrations inherit software supply-chain risks while introducing access to agent context and prompts. Reduce that exposure through reviewed dependencies, limited credential access, and monitored execution. When compromise occurs, contain affected endpoints and revoke exposed credentials together.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Strengthen Software Supply Chain Defense<\/h5><p>Protect developer endpoints, detect credential theft, and contain supply-chain threats faster with Hexnode UEM and XDR.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Start Your Free Trial! <\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>The MemTensor compromise turned legitimate AI memory packages into a credential-theft channel. Malicious releases on&#8230;<\/p>\n","protected":false},"author":6,"featured_media":1973,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[14,15],"class_list":["post-1953","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-supply-chain-attack","category-malware","product_category-extended-detection-and-response","tab_group-malware-and-ransomware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>MemTensor Compromise: AI Packages Steal Developer Secrets<\/title>\n<meta name=\"description\" content=\"Explore how the MemTensor compromise exposed developer secrets through npm and PyPI packages, and what security teams should do next.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/ai-memory-packages-become-credential-stealing-supply-chain-implants\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"MemTensor Compromise: AI Packages Steal Developer Secrets\" \/>\n<meta property=\"og:description\" content=\"Explore how the MemTensor compromise exposed developer secrets through npm and PyPI packages, and what security teams should do next.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/ai-memory-packages-become-credential-stealing-supply-chain-implants\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-24T07:14:50+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-28T06:18:04+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/AI-Memory-Packages-Become-Credential-Stealing-Supply-Chain-Implants.png?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Lily Anne\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Lily Anne\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ai-memory-packages-become-credential-stealing-supply-chain-implants\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ai-memory-packages-become-credential-stealing-supply-chain-implants\\\/\"},\"author\":{\"name\":\"Lily Anne\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/072b33718ec5df7cb7dbb9bae93044fa\"},\"headline\":\"AI Memory Packages Become Credential-Stealing Supply-Chain Implants\",\"datePublished\":\"2026-09-24T07:14:50+00:00\",\"dateModified\":\"2026-09-28T06:18:04+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ai-memory-packages-become-credential-stealing-supply-chain-implants\\\/\"},\"wordCount\":797,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ai-memory-packages-become-credential-stealing-supply-chain-implants\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/AI-Memory-Packages-Become-Credential-Stealing-Supply-Chain-Implants.png?format=webp\",\"articleSection\":[\"Supply Chain Attack\",\"Malware\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ai-memory-packages-become-credential-stealing-supply-chain-implants\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ai-memory-packages-become-credential-stealing-supply-chain-implants\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ai-memory-packages-become-credential-stealing-supply-chain-implants\\\/\",\"name\":\"MemTensor Compromise: AI Packages Steal Developer Secrets\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ai-memory-packages-become-credential-stealing-supply-chain-implants\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ai-memory-packages-become-credential-stealing-supply-chain-implants\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/AI-Memory-Packages-Become-Credential-Stealing-Supply-Chain-Implants.png?format=webp\",\"datePublished\":\"2026-09-24T07:14:50+00:00\",\"dateModified\":\"2026-09-28T06:18:04+00:00\",\"description\":\"Explore how the MemTensor compromise exposed developer secrets through npm and PyPI packages, and what security teams should do next.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ai-memory-packages-become-credential-stealing-supply-chain-implants\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ai-memory-packages-become-credential-stealing-supply-chain-implants\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ai-memory-packages-become-credential-stealing-supply-chain-implants\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/AI-Memory-Packages-Become-Credential-Stealing-Supply-Chain-Implants.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/AI-Memory-Packages-Become-Credential-Stealing-Supply-Chain-Implants.png?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"AI Memory Packages Become Credential-Stealing Supply-Chain Implants\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ai-memory-packages-become-credential-stealing-supply-chain-implants\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"AI Memory Packages Become Credential-Stealing Supply-Chain Implants\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/072b33718ec5df7cb7dbb9bae93044fa\",\"name\":\"Lily Anne\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"caption\":\"Lily Anne\"},\"description\":\"Content writer at Hexnode. Fueled by good coffee and the occasional cat cuddle, I enjoy crafting content that informs, connects, and resonates. Nothing excites me more than knowing my words have been read, appreciated, and maybe even bookmarked.\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/lily-anne\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"MemTensor Compromise: AI Packages Steal Developer Secrets","description":"Explore how the MemTensor compromise exposed developer secrets through npm and PyPI packages, and what security teams should do next.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/ai-memory-packages-become-credential-stealing-supply-chain-implants\/","og_locale":"en_US","og_type":"article","og_title":"MemTensor Compromise: AI Packages Steal Developer Secrets","og_description":"Explore how the MemTensor compromise exposed developer secrets through npm and PyPI packages, and what security teams should do next.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/ai-memory-packages-become-credential-stealing-supply-chain-implants\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-09-24T07:14:50+00:00","article_modified_time":"2026-09-28T06:18:04+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/AI-Memory-Packages-Become-Credential-Stealing-Supply-Chain-Implants.png?format=webp","type":"image\/png"}],"author":"Lily Anne","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Lily Anne","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/ai-memory-packages-become-credential-stealing-supply-chain-implants\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/ai-memory-packages-become-credential-stealing-supply-chain-implants\/"},"author":{"name":"Lily Anne","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/072b33718ec5df7cb7dbb9bae93044fa"},"headline":"AI Memory Packages Become Credential-Stealing Supply-Chain Implants","datePublished":"2026-09-24T07:14:50+00:00","dateModified":"2026-09-28T06:18:04+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/ai-memory-packages-become-credential-stealing-supply-chain-implants\/"},"wordCount":797,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/ai-memory-packages-become-credential-stealing-supply-chain-implants\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/AI-Memory-Packages-Become-Credential-Stealing-Supply-Chain-Implants.png?format=webp","articleSection":["Supply Chain Attack","Malware"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/ai-memory-packages-become-credential-stealing-supply-chain-implants\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/ai-memory-packages-become-credential-stealing-supply-chain-implants\/","url":"https:\/\/www.hexnode.com\/threat-watch\/ai-memory-packages-become-credential-stealing-supply-chain-implants\/","name":"MemTensor Compromise: AI Packages Steal Developer Secrets","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/ai-memory-packages-become-credential-stealing-supply-chain-implants\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/ai-memory-packages-become-credential-stealing-supply-chain-implants\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/AI-Memory-Packages-Become-Credential-Stealing-Supply-Chain-Implants.png?format=webp","datePublished":"2026-09-24T07:14:50+00:00","dateModified":"2026-09-28T06:18:04+00:00","description":"Explore how the MemTensor compromise exposed developer secrets through npm and PyPI packages, and what security teams should do next.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/ai-memory-packages-become-credential-stealing-supply-chain-implants\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/ai-memory-packages-become-credential-stealing-supply-chain-implants\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/ai-memory-packages-become-credential-stealing-supply-chain-implants\/#primaryimage","url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/AI-Memory-Packages-Become-Credential-Stealing-Supply-Chain-Implants.png?format=webp","contentUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/AI-Memory-Packages-Become-Credential-Stealing-Supply-Chain-Implants.png?format=webp","width":1340,"height":700,"caption":"AI Memory Packages Become Credential-Stealing Supply-Chain Implants"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/ai-memory-packages-become-credential-stealing-supply-chain-implants\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"AI Memory Packages Become Credential-Stealing Supply-Chain Implants"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/072b33718ec5df7cb7dbb9bae93044fa","name":"Lily Anne","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","caption":"Lily Anne"},"description":"Content writer at Hexnode. Fueled by good coffee and the occasional cat cuddle, I enjoy crafting content that informs, connects, and resonates. Nothing excites me more than knowing my words have been read, appreciated, and maybe even bookmarked.","url":"https:\/\/www.hexnode.com\/threat-watch\/author\/lily-anne\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1953","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1953"}],"version-history":[{"count":5,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1953\/revisions"}],"predecessor-version":[{"id":2022,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1953\/revisions\/2022"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1973"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1953"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1953"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}