mal-2026-16475

ossf_malicious_packages
Description

--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (91081756ee0d7e550180abd300ce4ed9634862248dd07ea9eed5fb740e4aaffc) On `import memos`, memos/__init__.py invokes configure_logging() which reaches memos._stage0.trigger(). That function locates a per-OS/arch prebuilt Go binary shipped inside the wheel at src/memos/.sckit/{darwin,linux,windows}-{amd64,arm64}/sckit (linux-amd64 is a 7.4MB ELF, sha256 c1b0998347b489582bae7b7f4930f9831d9ef4b6bc150cfd488ee1a43272dd36) and Popen-launches it detached (start_new_session=True, output silenced) with a base64 --config64 payload. The decoded configuration declares campaign_id "memos-semi-nuclear", an Ed25519 root_public key, state_dir $HOME/.memos/.cache/runtime, inventory_roots=["$HOME"], and three anonymous hex-subdomain fronts https://c747d139e7e9.skyleen.fr, https://73376a079d87.skyleen.fr and https://d4f77a3a8cb0.skyleen.fr with config/status/batch endpoints — instructing the launched agent to enumerate the installer's home directory and POST batches to attacker-controlled infrastructure. Separately, the package's PEP 517 build backend (sckit_poetry_build.py) wraps poetry.core.masonry and, when GITHUB_ENV is set, appends BASH_ENV=src/memos/_pypi_bridge.sh to $GITHUB_ENV so that any subsequent bash step in the same CI job auto-sources _pypi_bridge.sh; under a twine publish path this invokes _initial_ci_delivery.py to fetch and execute an Ed25519-signed emitter from https://10729e014d0e.skyleen.fr and reads $INPUT_PASSWORD and $PYPI_API_TOKEN before unsetting them, giving the attacker access to downstream publishing credentials. The combination of import-time detached execution of a bundled multi-arch binary, base64-obfuscated runtime manifest, anonymous hex-subdomain C2 fronts, declared $HOME inventory harvest, and a CI-only sideloader that steals publish tokens is a supply-chain implant. ## Source: kam193 (d17530b4f32046961be6354a73139dafa5a7d73ca9f7226dcf6bb3a3510bde20) Versions 2.0.34 were compromised. The package was compromised and contains a malicious executable. First discovered by Safedep. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-09-compr-memoryos Reasons (based on the campaign): - compromised-package

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

Weaknesses (CWE)
References
Linked Vulnerabilities

No linked vulnerabilities found.

{
  "affected": [
    {
      "database_specific": {
        "cwes": [
          {
            "cweId": "CWE-506",
            "description": "The product contains code that appears to be malicious in nature.",
            "name": "Embedded Malicious Code"
          }
        ],
        "indicators": {
          "evidence_files": [
            {
              "path": "src/memos/_stage0.py",
              "sha256": "881ea19936b0275f0d77c9d1a669b29595f7e274fef7bb7d82ec1690f8dbc591",
              "tlsh": "ad41e699cb283f8ca146423152117b6883a7c4437b0754ad34dc4dc8179b4aba0e48ff"
            },
            {
              "path": "sckit_poetry_build.py",
              "sha256": "497be589f382b321fa08d5583e7c7ff76daca18f988607a0051f8797b046ed86",
              "tlsh": "5621b734d21426a6a2f101e53922532182f7a06f4e426d28fd8cdd881f4e42a02f247d"
            }
          ],
          "package_integrity": [
            {
              "filename": "memoryos-2.0.34-py3-none-any.whl",
              "hashes": {
                "blake2b_256": "166972a6cc7f2a7a6ce286631bb176fb575dfd2378c2b74058a3e9b4cd0f1df9",
                "md5": "3d8db89d9fc419780fa557b5bbb6dd53",
                "sha256": "39ee644406829a4b630b31759c20478bc22d576d6a59b253ed86f72c360aa5ef"
              }
            },
            {
              "filename": "memoryos-2.0.34.tar.gz",
              "hashes": {
                "blake2b_256": "3e9a4d766a52dcabcbf440aa8f8f1eaf2adca041f93913271d8c342c20ae167c",
                "md5": "ecac3e301bc0b287fb4f5740a2cd8b8f",
                "sha256": "92b46d18fc553c494eda714f204459edb74c205bf53b18a9092bcf02c7a6c5be"
              }
            }
          ]
        }
      },
      "package": {
        "ecosystem": "PyPI",
        "name": "memoryos"
      },
      "versions": [
        "2.0.34"
      ]
    }
  ],
  "credits": [
    {
      "contact": [
        "inspector-research@amazon.com"
      ],
      "name": "Amazon Inspector",
      "type": "FINDER"
    },
    {
      "contact": [
        "https://github.com/kam193",
        "https://bad-packages.kam193.eu/"
      ],
      "name": "Kamil Mańkowski (kam193)",
      "type": "REPORTER"
    },
    {
      "contact": [
        "https://github.com/kam193",
        "https://bad-packages.kam193.eu/"
      ],
      "name": "Kamil Mańkowski (kam193)",
      "type": "ANALYST"
    }
  ],
  "database_specific": {
    "iocs": {
      "domains": [
        "c747d139e7e9.skyleen.fr",
        "73376a079d87.skyleen.fr",
        "d4f77a3a8cb0.skyleen.fr"
      ]
    },
    "malicious-packages-origins": [
      {
        "id": "pypi/2026-09-compr-memoryos/memoryos",
        "import_time": "2026-09-23T11:39:55.779888783Z",
        "modified_time": "2026-09-23T11:05:40Z",
        "sha256": "d17530b4f32046961be6354a73139dafa5a7d73ca9f7226dcf6bb3a3510bde20",
        "source": "kam193",
        "versions": [
          "2.0.34"
        ]
      },
      {
        "id": "pypi/2026-09-compr-memoryos/memoryos",
        "import_time": "2026-09-23T12:27:29.81554581Z",
        "modified_time": "2026-09-23T11:24:20.192213Z",
        "sha256": "f615efcaee7120884365656085be5fdd17450a486945e6154004e36ddab0ac89",
        "source": "kam193",
        "versions": [
          "2.0.34"
        ]
      },
      {
        "id": "IN-MAL-2026-020490",
        "import_time": "2026-09-23T14:19:31.842786769Z",
        "modified_time": "2026-09-23T14:10:14Z",
        "sha256": "91081756ee0d7e550180abd300ce4ed9634862248dd07ea9eed5fb740e4aaffc",
        "source": "amazon-inspector",
        "versions": [
          "2.0.34"
        ]
      },
      {
        "id": "pypi/2026-09-compr-memoryos/memoryos",
        "import_time": "2026-09-23T19:16:13.107645438Z",
        "modified_time": "2026-09-23T11:24:20.192213Z",
        "sha256": "86a27870b919aa000ef05a66cedd4622cbf521a2ea6867a579dbec8c90d66f77",
        "source": "kam193",
        "versions": [
          "2.0.34"
        ]
      }
    ]
  },
  "details": "\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (91081756ee0d7e550180abd300ce4ed9634862248dd07ea9eed5fb740e4aaffc)\nOn `import memos`, memos/__init__.py invokes configure_logging() which reaches memos._stage0.trigger(). That function locates a per-OS/arch prebuilt Go binary shipped inside the wheel at src/memos/.sckit/{darwin,linux,windows}-{amd64,arm64}/sckit (linux-amd64 is a 7.4MB ELF, sha256 c1b0998347b489582bae7b7f4930f9831d9ef4b6bc150cfd488ee1a43272dd36) and Popen-launches it detached (start_new_session=True, output silenced) with a base64 --config64 payload. The decoded configuration declares campaign_id \"memos-semi-nuclear\", an Ed25519 root_public key, state_dir $HOME/.memos/.cache/runtime, inventory_roots=[\"$HOME\"], and three anonymous hex-subdomain fronts https://c747d139e7e9.skyleen.fr, https://73376a079d87.skyleen.fr and https://d4f77a3a8cb0.skyleen.fr with config/status/batch endpoints — instructing the launched agent to enumerate the installer's home directory and POST batches to attacker-controlled infrastructure. Separately, the package's PEP 517 build backend (sckit_poetry_build.py) wraps poetry.core.masonry and, when GITHUB_ENV is set, appends BASH_ENV=src/memos/_pypi_bridge.sh to $GITHUB_ENV so that any subsequent bash step in the same CI job auto-sources _pypi_bridge.sh; under a twine publish path this invokes _initial_ci_delivery.py to fetch and execute an Ed25519-signed emitter from https://10729e014d0e.skyleen.fr and reads $INPUT_PASSWORD and $PYPI_API_TOKEN before unsetting them, giving the attacker access to downstream publishing credentials. The combination of import-time detached execution of a bundled multi-arch binary, base64-obfuscated runtime manifest, anonymous hex-subdomain C2 fronts, declared $HOME inventory harvest, and a CI-only sideloader that steals publish tokens is a supply-chain implant.\n\n## Source: kam193 (d17530b4f32046961be6354a73139dafa5a7d73ca9f7226dcf6bb3a3510bde20)\nVersions 2.0.34 were compromised.\n\n\nThe package was compromised and contains a malicious executable. First discovered by Safedep.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-09-compr-memoryos\n\n\nReasons (based on the campaign):\n\n\n - compromised-package\n",
  "id": "MAL-2026-16475",
  "modified": "2026-09-23T19:18:08.758805835Z",
  "published": "2026-09-23T11:05:40Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://safedep.io/memtensor-sckit-worm-npm-pypi/"
    },
    {
      "type": "EVIDENCE",
      "url": "https://www.virustotal.com/gui/file/8f647f17a1934679c4095e21bee2b9bd83e28476603758bc91408a0c8443e3b4/detection"
    },
    {
      "type": "WEB",
      "url": "https://bad-packages.kam193.eu/pypi/campaign/2026-09-compr-memoryos"
    },
    {
      "type": "PACKAGE",
      "url": "https://pypi.org/project/MemoryOS/2.0.34/"
    }
  ],
  "schema_version": "1.7.4",
  "summary": "Malicious code in memoryos (PyPI)"
}
View JSON API Download JSON