Tomas is directionally right. Published reporting identifies malicious npm versions @memtensor/memos-cloud-openclaw-plugin 0.1.21, 0.1.23, and 0.1.25, triggered during OpenClaw startup or memory recall, and PyPI MemoryOS 2.0.34, triggered when memos is imported. Those are reported mechanics rather than findings I can independently validate against binaries or hashes here. Reports also describe propagation-related functionality involving repositories, package releases, or CI workflows, but do not establish successful self-propagation into other public packages. “Worm-capable” is defensible; “confirmed worm” is not.
The highest-confidence package artifacts are those exact versions in lockfiles, caches, container layers, build logs, and SBOMs. On hosts, hunt for current or historical sckit execution and unexpected native binaries launched beneath Python or OpenClaw around import, startup, and memory-recall events. For network telemetry, reporting consistently identifies skyleen.fr and its subdomains; inspect DNS, proxy, firewall, and EDR records for connections rather than treating the domain alone as proof of compromise. No verified hashes, file paths, mutexes, persistence entries, or stable command lines are available in the cited reporting.
The reported targeting scope includes npm, PyPI, GitHub, GitLab, AWS, Vault, SSH, Hugging Face, Slack, Stripe, SendGrid, and selected OpenClaw prompt data. That establishes what the stealer reportedly searches for—not which secrets it successfully accessed or exfiltrated on a given host. Rotation alone is inadequate where execution occurred and telemetry cannot bound file writes, child processes, persistence, or outbound traffic; where privileged cloud or publishing credentials were accessible; or where repositories, workflows, images, or releases may have been altered. Rebuild affected workstations, runners, or OpenClaw hosts from trusted images in those cases, then audit CI and registry integrity separately. Mere installation without any runtime trigger does not establish payload execution.