A popular npm package used by developers building AI agent applications was silently weaponized this week, turning routine software installations into a gateway for credential theft, cryptocurrency wallet raids, and self-propagating supply chain infections.
On October 8, 2026, security researchers at Socket confirmed that version 0.5.144 of the tensorlake npm package — the official TypeScript SDK for Tensorlake’s AI agent sandbox and cloud platform — had been compromised with a variant of the Shai-Hulud worm, a self-replicating malware strain that has been tearing through the JavaScript ecosystem since August.
What Happened
The attack began on October 7 at approximately 01:20 UTC, when the threat actor pushed malicious code to the main branch of the tensorlakeai/tensorlake GitHub repository using a compromised maintainer identity. The commits were verified, making them appear legitimate. After roughly 20 hours, the repository’s automated release workflow published the poisoned version 0.5.144 to the npm registry.
Socket’s automated detection flagged the malicious release within 11 minutes of publication, but any developer or CI pipeline that installed the package in that window — or before the alert reached them — was exposed. The tensorlake package has over 100,000 lifetime downloads and roughly 12,000 weekly installs, making the blast radius potentially significant.
This incident is part of the larger ChainDrop campaign, which first surfaced in early August 2026 when the same Shai-Hulud malware compromised the widely used keyv and cacheable npm packages. The attack chain, file structure, and payload obfuscation are nearly identical to those earlier waves.
How the Attack Works
The malware’s entry point is deceptively simple. The poisoned package includes a preinstall hook — a script that runs automatically during npm install, before the developer ever imports or uses the SDK in their code. The hook launches an obfuscated loader (lib/setup.mjs) that drops the Bun JavaScript runtime and uses it to execute the main payload, lib/Math_Symbol.js.
Once running, the payload fans out across the infected machine with alarming thoroughness. It harvests:
- npm and GitHub tokens, including OIDC token exchange credentials
- AWS credentials via IMDS, ECS metadata, Secrets Manager, and SSM Parameter Store
- HashiCorp Vault secrets from local instances, including Kubernetes and AWS authentication paths
- Kubernetes service-account tokens and kubeconfig files
- SSH keys,
.envfiles, and cryptocurrency wallet data - Browser credentials and cookies using a dropped HackBrowserData binary
- AI coding tool configurations — including MCP server configs and settings for Claude Code, Cursor, Kiro, Windsurf, and Zed
The command-and-control infrastructure is notably sophisticated. Rather than hardcoding a C2 domain that defenders could easily block, the worm resolves its endpoint by reading the latest transaction on an attacker-controlled Ethereum wallet, querying approximately 30 public RPC endpoints. The resolved domain in this wave is iseekaigogo[.]com. If the blockchain resolver fails, the malware falls back to GitHub, where it stages encrypted stolen data in a public repository.
The Worm Spreads
What makes Shai-Hulud particularly dangerous is its self-propagating nature. After stealing a developer’s npm publishing credentials and GitHub tokens, the worm enumerates every package tied to the victim’s identity. It then builds Sigstore provenance — the cryptographic attestation system meant to verify package authenticity — and republishes compromised versions of those packages. In effect, one infected developer can silently poison dozens of packages downstream, each of which infects its own installers.
The worm also plants persistence mechanisms in development environments. It writes malicious configuration files into reachable repositories — specifically .claude/settings.json and .vscode/tasks.json — so the payload re-executes whenever a developer opens the project in Claude Code or VS Code. Strings in the code also suggest it creates fake Copilot and Dependabot GitHub Actions workflows to maintain a foothold in CI pipelines.
The Dead Man’s Switch
Perhaps the most chilling feature is Shai-Hulud’s “hostage token” mechanism. The malware installs a PowerShell monitor as a Windows scheduled task (triggered on logon) that continuously polls GitHub’s API using the stolen token. If the victim revokes the compromised token — the natural first response upon discovering a breach — the monitor detects the revocation and executes an attacker-supplied handler via Invoke-Expression. The code includes the string IfYouRevokeThisTokenItWillWipeTheComputerOfTheOwner, and previous Shai-Hulud waves have reportedly followed through on that threat with destructive routines.
This creates a painful dilemma for incident responders: revoking stolen credentials is standard procedure, but doing so on an infected machine may trigger data destruction.
Who Is Affected
Any developer, CI/CD pipeline, or server environment that installed tensorlake@0.5.144 should be considered compromised. Because the malware runs during installation via the preinstall hook, simply having the package in a dependency tree is enough — there is no need to import or call any of its functions.
The broader risk extends to the entire downstream supply chain. If a compromised developer’s credentials were used to republish other packages, those packages and their users may also be affected. The full scope of secondary infections is still being assessed.
What You Should Do
Security teams and developers should take the following steps immediately:
- Check for exposure. Search your lockfiles, build logs, manifests, and deployed artifacts for
tensorlake@0.5.144. The maliciouslib/setup.mjshas SHA-256 hash25a0735d0db7dc40e5d45ce42d9c106067e6a66e184d967cfecfab17c3bcb5ef, andlib/Math_Symbol.jshas hashb50a00900399ba99fb6ce1fc151519cb99d44320ef2a631f2237e1aea0ad6fec. - Treat affected systems as fully compromised. Removing the npm package does not remove the implant. Isolate affected hosts and plan a full rebuild from trusted sources.
- Rotate credentials carefully. Before revoking GitHub tokens on an infected machine, ensure persistence mechanisms (especially the PowerShell scheduled task) have been removed first to avoid triggering the dead man’s switch. Rotate all AWS keys, SSH keys, Vault tokens, Kubernetes credentials, and npm tokens from a known-clean environment.
- Audit for secondary spread. Check your npm packages for unauthorized publishes and your GitHub repositories for unexpected workflow files,
.claude/settings.json, or.vscode/tasks.jsonadditions. - Disable lifecycle scripts in CI. Running
npm installwith--ignore-scriptsin build pipelines prevents preinstall hooks from executing, at the cost of breaking packages that legitimately need them.
The Bigger Picture
The Tensorlake compromise is the latest in a drumbeat of software supply chain attacks that have accelerated sharply in 2026. The ChainDrop campaign alone has hit hundreds of npm packages since August, and the Shai-Hulud worm’s self-replicating design means each compromise multiplies the attack surface exponentially.
The targeting of AI development tool configurations — Claude Code, Cursor, Kiro, Windsurf, and Zed — signals a deliberate evolution. As AI-assisted coding becomes ubiquitous, attackers are adapting to steal not just traditional credentials but the configuration files that govern how AI agents interact with codebases and cloud services. The MCP (Model Context Protocol) server configurations targeted by this malware can contain API keys, database connection strings, and other sensitive data that AI tools use to operate on a developer’s behalf.
For organizations relying on the npm ecosystem, this is another reminder that every npm install is an act of trust — and that trust continues to be exploited at scale.
Leave a Reply