Security & privacy

Tensorlake npm package compromised in Shai-Hulud supply chain attack

Malicious version 0.5.144 of the Tensorlake SDK was published to npm, delivering a credential-stealing worm that targets AI infrastructure and cloud secrets.

Illustration of a compromised npm package box revealing malicious code inside
Illustration created for this article

The Tensorlake npm package, a TypeScript SDK for building applications on Tensorlake’s cloud services, was compromised in a sophisticated supply chain attack. On October 8, 2026, security researchers identified that version 0.5.144 contained obfuscated malware designed to steal credentials and propagate itself across developer environments.

This incident is part of the broader ChainDrop campaign, which utilizes the Shai-Hulud worm variant to target software supply chains. The malicious package has since been removed from the npm registry, but developers who installed it during the window of exposure remain at risk of persistent unauthorized access and data exfiltration.

What happened

Attackers gained access to the Tensorlake repository and pushed malicious code to the main branch under a maintainer’s name. The first rogue commit occurred on October 7, 2026, at 01:20 a.m. UTC. The following day, the repository’s automated release workflow published version 0.5.144 to the public npm registry. This sequence suggests the attackers compromised the maintenance pipeline rather than just the package distribution channel.

The compromised package includes a preinstall hook that executes a JavaScript loader file named "package/lib/setup.mjs". This loader launches the primary payload, "package/lib/Math_Symbol.js", using the Bun runtime. The payload is an obfuscated worm that harvests credentials, establishes persistence on the host system, and executes remotely supplied code. Security firm Socket noted that the malware’s capabilities extend far beyond simple keylogging, as it can maintain access even after the dependency is removed.

The worm is designed to be self-propagating. It enumerates other packages associated with the victim’s publishing identity, builds fake Sigstore provenance records, and republishes compromised versions of those packages. This mechanism allows the infection to spread laterally through the developer’s own software ecosystem, potentially impacting downstream users who trust the developer’s other projects.

Key details

  • Malicious version: Only version 0.5.144 of the tensorlake package is confirmed to be compromised.
  • Payload execution: The malware uses a preinstall hook to run an obfuscated loader via the Bun runtime.
  • Data targeted: The stealer harvests npm tokens, GitHub tokens, AWS credentials, HashiCorp Vault secrets, Kubernetes credentials, SSH keys, .env files, and cryptocurrency wallets.
  • AI tool integration: It specifically targets configuration files for AI coding assistants like Anthropic Claude, Cursor, Kiro, Windsurf, and Zed.
  • Persistence mechanism: The malware writes settings to .claude/settings.json and .vscode/tasks.json, ensuring it runs when developers open projects in these editors.
  • Command and control: The worm uses an Ethereum contract to resolve its C2 endpoint (iseekaigogo[.]com) and uses GitHub repositories as a fallback for staging stolen data.

Background

Supply chain attacks occur when attackers compromise a trusted third-party component, such as a library or framework, to distribute malware to its users. In this case, the attack vector is the npm registry, the default package manager for Node.js and TypeScript ecosystems. Because developers often trust packages from known maintainers, they may not scrutinize updates closely, allowing malicious code to enter production environments easily.

The Shai-Hulud worm is notable for its focus on AI agent infrastructure. As more companies integrate AI coding assistants into their workflows, these tools become high-value targets. They often have broad access to codebases, environment variables, and internal APIs. By targeting the configuration files of tools like Claude Code and VS Code, the attackers ensure that their malware activates whenever a developer interacts with their project, creating a persistent foothold that is difficult to eradicate with standard package removal.

Why it matters

For teams that run their own software, this incident highlights the fragility of trust in open-source dependencies. Even if you vet a package initially, a compromised maintainer account or build pipeline can inject malware at any time. The fact that the worm republishes other packages under the victim’s identity means that a single compromise can damage your reputation and infect your entire portfolio of tools. This lateral movement makes containment significantly harder than removing a single bad dependency.

The specific targeting of AI coding assistants poses a new risk for development workflows. These tools often operate with elevated privileges to read and write code, access local files, and interact with terminal commands. If an attacker gains control over these agents, they can exfiltrate sensitive logic, insert backdoors into source code, or steal secrets stored in local environment files. For self-hosting teams, this means that local development machines are now critical security perimeters that require the same level of protection as production servers.

Furthermore, the "hostage token" tactic demonstrates an aggressive escalation strategy. If a victim revokes a stolen GitHub token, the malware detects this change and executes a destructive PowerShell routine. This anti-forensic measure discourages simple remediation steps like token rotation and forces organizations to perform full system cleanups. It underscores the need for comprehensive incident response plans that account for persistent threats embedded in development tools.

What you can do

  • Check installed versions: Immediately verify if version 0.5.144 of the tensorlake package is present in your project dependencies or lock files.
  • Rotate all credentials: If you installed the malicious version, rotate all npm tokens, GitHub tokens, AWS keys, SSH keys, and any other secrets accessible from your development environment.
  • Inspect AI configurations: Check your repositories for unexpected changes to .claude/settings.json and .vscode/tasks.json files, and remove any suspicious entries.
  • Audit published packages: Review your other published npm packages for unauthorized versions or changes to provenance records that may indicate lateral propagation.
  • Monitor CI/CD pipelines: Look for unfamiliar GitHub Actions workflows or commits referencing fake Copilot/Dependabot processes in your repositories.
  • Scan for persistence: Use endpoint detection tools to search for the HackBrowserData binary and monitor for unusual PowerShell activity involving Invoke-Expression.

"Any secrets accessible to the executing process may be exposed, and persistence can retain attacker access after the affected dependency is removed." — Socket

More news

All news