{"slug": "tensorlake-npm-package-compromised-to-deliver-shai-hulud-credential-stealing", "title": "Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm", "summary": "The Tensorlake TypeScript SDK npm package was compromised in a ChainDrop / Shai-Hulud supply chain attack, with malicious version 0.5.144 harvesting credentials, exfiltrating secrets, establishing persistence, and executing remotely supplied code, according to Socket. Socket said the release contains a preinstall hook launching an obfuscated loader that runs the credential-stealing, self-propagating worm via the Bun runtime, targeting npm and GitHub tokens, AWS credentials, HashiCorp Vault, Kubernetes credentials, SSH keys, .env files, cryptocurrency wallets, and configuration and MCP files for Anthropic Claude, Cursor, Kiro, Windsurf, and Zed. StepSecurity reported the malicious files were pushed to the main branch of tensorlakeai/tensorlake under a maintainer's name, with the first rogue commit on October 7, 2026, at 01:20 a.m. UTC and version 0.5.144 published to npm a day later; version 0.5.144 is no longer available for download from the npm registry.", "body_md": "The npm package known as “[tensorlake](https://www.npmjs.com/package/tensorlake?activeTab=versions),” a TypeScript software development kit (SDK) for [Tensorlake](https://www.tensorlake.ai) applications, sandboxes, and cloud services, was [compromised](https://github.com/tensorlakeai/tensorlake/issues/1014) as part of a [ChainDrop / Shai-Hulud](https://thehackernews.com/2026/08/open-vsx-removes-77-malicious-evil-twin.html) supply chain attack.\n\nThe malicious version 0.5.144 “contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code,” Socket [said](https://socket.dev/blog/tensorlake-compromise). Version 0.5.144 is no longer available for download from the npm package registry.\n\nAn analysis of the compromised release shows that it contains a preinstall hook designed to launch a JavaScript file (“package/lib/setup.mjs”), an obfuscated loader that launches the main credential-stealing and self-propagating worm (“package/lib/Math_Symbol.js”) using the Bun runtime.\n\nThe stealer malware is designed to harvest credentials across local files, CI environments, Kubernetes, and Vault sources. It also [drops](https://x.com/OliverAikido/status/2108012888304853260) the [HackBrowserData](https://thehackernews.com/2024/12/new-glutton-malware-exploits-popular.html) binary, exfiltrates the collected data, establishes persistence on the host, and facilitates the execution of remotely-supplied code.\n\n“That combination extends the risk beyond a single stolen API key,” Socket said. “Any secrets accessible to the executing process may be exposed, and persistence can retain attacker access after the affected dependency is removed.”\n\nThe types of data stolen by the malware are below –\n\n- npm tokens\n- GitHub tokens\n- Amazon Web Services (AWS) credentials and secrets\n- HashiCorp Vault\n- Kubernetes credentials\n- SSH keys\n- .env files\n- Cryptocurrency wallets\n- Messaging app data\n- Configuration and MCP files associated with Anthropic Claude, Cursor, Kiro, Windsurf, and Zed\n\n“To propagate, the worm enumerates packages associated with the victim’s publishing identity, builds Sigstore provenance, and republishes compromised versions,” Socket explained. “Strings referencing a fake Copilot/Dependabot workflow suggest it also plants GitHub Actions workflows.”\n\nThe malware also makes use of an Ethereum contract to resolve its command-and-control (C2) endpoint (“iseekaigogo[.]com”), with GitHub acting as a fallback mechanism to stage the encrypted stolen data in a public repository with the description “Shai-Hulud: Here We Go Again.”\n\nIn addition, there exists a “hostage token” component that uses a PowerShell monitor to repeatedly poll “api.github.com/user” using the stolen GitHub token to check if the token is valid. Should the victim take steps to revoke the token, the monitor proceeds to execute an attacker-supplied handler through the “Invoke-Expression” cmdlet to execute PowerShell code designed to likely trigger a destructive routine – a tactic observed in [earlier Shai-Hulud waves](https://thehackernews.com/2026/05/mini-shai-hulud-worm-compromises.html).\n\nAccording to StepSecurity, the malicious files were pushed to the main branch of tensorlakeai/tensorlake under a maintainer’s name, after which the package was released from that same repository. The [first rogue commit](https://github.com/tensorlakeai/tensorlake/commit/e90c47bbb208e99cac8aa678405b2133f6cb3f52) took place on October 7, 2026, at 01:20 a.m. UTC. A day later, the repository’s release workflow [published](https://github.com/tensorlakeai/tensorlake/tree/6386121c561e74fec143a138d5cc3d3bbabdfe8c/typescript/lib) 0.5.144 to npm.\n\n“The malware also writes .claude/settings.json and .vscode/tasks.json files into repos it can reach, so it runs again when someone opens the project in Claude Code or VS Code,” StepSecurity’s Ashish Kurmi [said](https://www.stepsecurity.io/blog/tensorlake-npm-compromised-hostage-token-worm).\n\n[ChainDrop](https://thehackernews.com/2026/08/open-vsx-removes-77-malicious-evil-twin.html) was first documented in early August 2026 in connection with the compromise of hundreds of npm packages, including [Keyv and Cacheable](https://thehackernews.com/2026/08/keyv-linked-npm-worm-poisons-hundreds.html), that were found to contain a Mini Shai-Hulud variant with a self-propagating credential-stealing worm delivered through an obfuscated Bun-based JavaScript payload.\n\nThe development extends the supply chain attack to artificial intelligence (AI) agent infrastructure, once again highlighting how threat actors are increasingly [targeting AI tools and services](https://thehackernews.com/2026/10/poellm-malware-infects-3400-servers-to.html) to extract valuable data from enterprises. Users who have installed the malicious version are advised to remove it immediately and rotate their credentials.", "url": "https://wpnews.pro/news/tensorlake-npm-package-compromised-to-deliver-shai-hulud-credential-stealing", "canonical_source": "https://www.swapupdate.in/tensorlake-npm-package-compromised-to-deliver-shai-hulud-credential-stealing-worm-2/", "published_at": "2026-10-08 07:36:21+00:00", "updated_at": "2026-10-08 08:47:55.569118+00:00", "lang": "en", "topics": ["ai-safety", "ai-tools", "developer-tools", "ai-agents"], "entities": ["Tensorlake", "npm", "Socket", "StepSecurity", "Shai-Hulud", "ChainDrop", "HackBrowserData", "Ashish Kurmi"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/tensorlake-npm-package-compromised-to-deliver-shai-hulud-credential-stealing", "markdown": "https://wpnews.pro/news/tensorlake-npm-package-compromised-to-deliver-shai-hulud-credential-stealing.md", "text": "https://wpnews.pro/news/tensorlake-npm-package-compromised-to-deliver-shai-hulud-credential-stealing.txt", "jsonld": "https://wpnews.pro/news/tensorlake-npm-package-compromised-to-deliver-shai-hulud-credential-stealing.jsonld"}}