
Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm
The npm package tensorlake, a TypeScript SDK, was compromised in a ChainDrop supply chain attack. Malicious version 0.5.144 delivered a self-propagating credential-stealing worm targeting npm, GitHub, AWS, Vault, and Kubernetes secrets.
The npm package "tensorlake," a TypeScript SDK for Tensorlake applications, sandboxes, and cloud services, has been compromised as part of a ChainDrop / Shai-Hulud supply chain attack. According to Socket, the malicious version 0.5.144 "contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code." The version is no longer available for download from the npm package registry.
How the Compromise Worked
Analysis of the compromised release shows it contains a preinstall hook designed to launch a JavaScript file (package/lib/setup.mjs), an obfuscated loader that launches the main credential-stealing and self-propagating worm (package/lib/Math_Symbol.js) using the Bun runtime. The stealer is designed to harvest credentials across local files, CI environments, Kubernetes, and Vault sources. It also drops the HackBrowserData binary, exfiltrates the collected data, establishes persistence on the host, and facilitates the execution of remotely supplied code.
Socket warned that the combination extends the risk beyond a single stolen API key. "Any secrets accessible to the executing process may be exposed, and persistence can retain attacker access after the affected dependency is removed."
Data Targeted and Propagation
The malware steals npm tokens, GitHub tokens, Amazon Web Services credentials and secrets, HashiCorp Vault data, Kubernetes credentials, SSH keys, .env files, cryptocurrency wallets, messaging app data, and configuration and MCP files associated with Anthropic Claude, Cursor, Kiro, Windsurf, and Zed.
To propagate, the worm enumerates packages associated with the victim's publishing identity, builds Sigstore provenance, and republishes compromised versions. Strings referencing a fake Copilot/Dependabot workflow suggest it also plants GitHub Actions workflows. The malware uses an Ethereum contract to resolve its command-and-control endpoint (iseekaigogo[.]com), with GitHub acting as a fallback mechanism to stage the encrypted stolen data in a public repository with the description "Shai-Hulud: Here We Go Again."
Hostage Token Mechanism
A "hostage token" component uses a PowerShell monitor to repeatedly poll api.github.com/user using the stolen GitHub token to check whether the token is valid. Should the victim revoke the token, the monitor proceeds to execute an attacker-supplied handler through the Invoke-Expression cmdlet, likely triggering a destructive routine, a tactic observed in earlier Shai-Hulud waves.
Timeline and Response
According to StepSecurity, the malicious files were pushed to the main branch of tensorlakeai/tensorlake under a maintainer's name, after which the package was released from that same repository. The first rogue commit took place on October 7, 2026, at 01:20 a.m. UTC. A day later, the repository's release workflow published 0.5.144 to npm.
StepSecurity's Ashish Kurmi noted that the malware writes .claude/settings.json and .vscode/tasks.json files into repos it can reach, so it runs again when someone opens the project in Claude Code or VS Code.
ChainDrop was first documented in early August 2026 in connection with the compromise of hundreds of npm packages, including Keyv and Cacheable, which were found to contain a Mini Shai-Hulud variant with a self-propagating credential-stealing worm delivered through an obfuscated Bun-based JavaScript payload. The latest incident extends the supply chain attack to AI agent infrastructure, once again highlighting how threat actors are increasingly targeting AI tools and services to extract valuable data from enterprises.
Users who have installed the malicious version are advised to remove it immediately and rotate their credentials.
Sources: The Hacker News
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.