HomeSecurityTensorlake npm: Credential theft via Shai-Hulud worm

Tensorlake npm: Credential theft via Shai-Hulud worm

The npm package has been the target of a supply chain attack, with attackers exploiting access to a repository to release a malicious build containing the infamous Shai-Hulud worm. The infected version 0.5.144 of TypeScript SDK for applications, sandboxes, and cloud services was found to steal credentials, extract secrets, install persistence, and execute code provided remotely by attackers. This build is no longer available in the npm registry, but systems that installed it while it was available remain at risk.

Tensorlake npm package breach Shai-Hulud worm stealing credentials

According to analysis by security researchers at Socket and StepSecurity, the first malicious commit to the tensorlakeai/tensorlake was made on October 7, 2026, at 01:20 UTC, under the name of a legitimate maintainer of the project. A day later, the repository’s release workflow automatically published version 0.5.144 to npm. This demonstrates how dangerous can be: an attacker can deliver malicious code through the legitimate update process, with no obvious signs of compromise to end users.

The attack is part of the broader ChainDrop/Shai-Hulud, which first appeared earlier this year and targeted hundreds of npm packages, including the popular Keyv and Cacheable. In that campaign, the payload used an obfuscated worm based on the Bun runtime to steal credentials and spread through development environments. Subsequent reports from JFrog linked a broader Shai-Hulud variant to more than 400 npm packages and over 1,700 package versions, while a May 2026 published over 400 malicious versions across 172 packages in about five hours.

See also: Mini Shai-Hulud attacks AntV npm packages via compromised account

Technical Analysis: How Tensorlake npm malware works

The infected version of Tensorlake contained a preinstall hook designed to launch a JavaScript file ( package/lib/setup.mjs ). This file acts as an obfuscated loader that launches the main credentials stealer and worm ( package/lib/Math_Symbol.js ) using the Bun runtime . The use of Bun — a legitimate JavaScript runtime — makes it difficult to detect, as security systems that rely solely on monitoring Node.js processes may not detect it.

The malware is designed to collect credentials from local files, CI/CD environments, Kubernetes, and HashiCorp Vault repositories . It also installs the HackBrowserData binary to extract data stored in the browser, exports the collected data, installs persistence on the host, and facilitates remote code execution. The types of data it steals include: Amazon Web Services (AWS) credentials and secrets , Kubernetes credentials , cryptocurrency wallets , and configuration files related to AI tools such as Anthropic Claude , Cursor, Kiro, Windsurf, and Zed.

Tensorlake npm - SecNews.gr

The worm's propagation mechanism is particularly worrisome: it enumerates packages associated with the victim's publishing identity, creates Sigstore provenances , and republishes infected builds. It also plants GitHub Actions workflows in repositories it can reach, writing .claude/settings.json and .vscode/tasks.jsonto be re-executed when someone opens the project in Claude Code or VS Code. This means that even if the infected dependency is removed, the attacker can still have access.

Tensorlake npm and the "hostage token" mechanism

One of the most sophisticated features of the Tensorlake npm malware is the so-called “hostage token” component. This uses a PowerShell monitor that repeatedly checks api.github.com/user using the stolen GitHub tokento verify that the token is still valid. If the victim attempts to revoke the token, the monitor executes a handler provided by the attacker via the Invoke-Expression, executing PowerShell that likely triggers a destructive routine. This tactic has been observed in previous Shai-Hulud waves.

See also: Mini Shai-Hulud Worm: Infects TanStack, Mistral AI and other Packages

To communicate with the command and control (C2) server, the malware uses an Ethereum smart contract to resolve the endpoint (iseekaigogo[.]com), with GitHub acting as an alternative mechanism for storing encrypted stolen data in a public repository with the description “Shai-Hulud: Here We Go Again”. Using blockchain for C2 resolution is a sophisticated technique that makes it difficult to block communication, as it is not enough to simply block a domain.

Article Image: Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer

This attack expands the scope of supply chain attacks to AI agent infrastructure , highlighting once again how threat actors are increasingly turning to AI tools and services to extract valuable data from businesses. In September 2026 , Aikido researchers detected the same payload in four npm packages after a 111-day gap , demonstrating that hash-based detection can fail when malware is repackaged or reintroduced after a period of inactivity.

Protection against Tensorlake type attacks npm supply chain

Organizations that may have installed Tensorlake npm version 0.5.144 should treat affected development machines, build agents, and CI runners as potentially compromised. The first step is to immediately remove the malicious version and install a verified clean version , after checking the project's release history. Rebooting from a trusted lockfile and clean, isolated systems is preferable to simply reinstalling on top of an existing environment.

It is critical to immediately switch over all credentials that were accessible on the affected systems: npm tokens , GitHub tokens , cloud keys, Kubernetes credentials, Vault tokens, SSH keys, browser-stored secrets, and CI/CD variables . Also, revoke short-lived OIDC credentials and review cloud audit logs. GitHub repositories should be monitored for unauthorized commits, workflow changes, new secrets , and unexpected package releases.

See also: 'Mini Shai-Hulud': SAP-Related npm Packages Compromised with Credential Stealer

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Article Image: 18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

For long-term protection, organizations should implement a least privilege policy for package publishers, require phishing-resistant multifactor authentication for npm, GitHub, and cloud accounts, pin accurate dependency versions, and verify integrity hashes. Monitoring package installation behavior and endpoint activity is essential, as — as the Shai-Hulud incidents have shown — registry scanning and signature matching alone are not enough. According to The Hacker News, users who have installed the malicious version are urged to immediately remove it and change their credentials.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS