# MemTensor OpenClaw Plugin Ships sckit Credential Worm

> LLM-readable article card for ThreatFrontier.com. Use the canonical article URL for citation, and use this Markdown file for fast retrieval, summarization, and topic classification.

## Canonical Source
- [Canonical article](https://test.threatfrontier.com/articles/memtensor-openclaw-plugin-memoryos-sckit-worm): Full public article page.
- [Article LLM summary](https://test.threatfrontier.com/articles/memtensor-openclaw-plugin-memoryos-sckit-worm/llms.txt): Machine-readable summary for this article.
- [Site LLM index](https://test.threatfrontier.com/llms.txt): Machine-readable map of public ThreatFrontier coverage.

## Article Metadata
- Title: MemTensor OpenClaw Plugin Ships sckit Credential Worm
- Summary: Poisoned @memtensor/memos-cloud-openclaw-plugin 0.1.21, 0.1.23, 0.1.25 and MemoryOS 2.0.34 carry sckit, a Go worm. How CI leaked the tokens, and what to rotate.
- Published: Oct 2, 2026, 8:05 AM EDT
- Updated: Oct 2, 2026, 8:05 AM EDT
- Category: Supply Chain
- Primary topic: Supply Chain Attack
- Authors: Alex Kim
- Read time: 8 min
- Language: en_US
- Publication time zone: America/New_York (U.S. Eastern Time)
- Access: Free to read

## Topic Links
- [Supply Chain](https://test.threatfrontier.com/categories/supply-chain): Category archive for related coverage.
- [Supply Chain Attack](https://test.threatfrontier.com/tags/supply-chain-attack): 2 public articles in this topic.

## Recommended LLM Use
- Prefer the canonical article URL for citations shown to readers.
- Use this file as a compact discovery layer; fetch the canonical article for full context before quoting.
- Do not infer draft, private, API, or media-library URLs from this file.
