PYSEC-2026-3987

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/MemoryOS/PYSEC-2026-3987.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2026-3987
Aliases
Published
2026-09-23T19:52:25Z
Modified
2026-09-23T20:15:02Z
Summary
MemoryOS 2.0.34 was published with a credential-stealing binary
Details

An attacker with write access to the GitHub repository pushed malicious commits and tagged v2.0.34, and the project's own GitHub Actions release workflow built and uploaded 2.0.34 to PyPI. Importing the package runs memos/_stage0.py, which launches a bundled sckit binary that collects credentials (.pypirc, .npmrc, .git-credentials, SSH keys, token-like environment variables) and sends them to *.skyleen[.]fr.

Remove 2.0.34 and rotate any credentials reachable from affected machines.

  • wheel SHA256: 39ee644406829a4b630b31759c20478bc22d576d6a59b253ed86f72c360aa5ef
  • sdist SHA256: 92b46d18fc553c494eda714f204459edb74c205bf53b18a9092bcf02c7a6c5be
References
Credits
    • Kamil MaƄkowski - REPORTER
    • Mike Fiedler - COORDINATOR

Affected packages

PyPI / memoryos

Package

Affected ranges

Affected versions

2.*
2.0.34

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/MemoryOS/PYSEC-2026-3987.yaml"