MemTensor's OpenClaw Plugin and MemoryOS Shipped the sckit Credential Worm
Pushed commits made MemTensor's own GitHub Actions jobs leak npm and PyPI tokens. Four releases then shipped sckit, a Go worm that steals developer secrets.
· 8 minTopic
Coverage tagged supply chain attack.
Pushed commits made MemTensor's own GitHub Actions jobs leak npm and PyPI tokens. Four releases then shipped sckit, a Go worm that steals developer secrets.
· 8 minHugging Face flaws and OpenAI integration paths have produced remote code execution, secret harvesting and cross-tenant exfiltration in real deployments.
· 6 min