Security Researcher @AikidoSecurity. Previously @SecCodeWarrior, co-founder at Adversaryio & Principal Security Engineer/Partner @thesyndis. Opinions all my own
We're tracking the "supplychain.local" worm, which hit the MemTensor npm and pypi packages:
npm: [@]memtensor/memos-cloud-openclaw-plugin@0.1.25
pypi: MemoryOS@2.0.34
It contains a novel worm, written in Go. Seems likely to be written by LLMs.