Skip to main content
Emerging ThreatsMalware & Ransomware

Malware Worm Exploits Tensorlake npm Package to Steal Credentials

Brightly-lit coding workspace with laptop and development tools, subtle network infrastructure in background.

The first rogue commit took place on October 7, 2026, at 01:20 a.m. UTC, and a day later the repository’s release workflow published a compromised tensorlake package as version 0.5.144.

Timeline: October 7–8, 2026 — commits, release, and takedown

According to StepSecurity, malicious files were pushed to the main branch of tensorlakeai/tensorlake under a maintainer’s name on October 7, 2026, at 01:20 a.m. UTC. The repository’s release workflow then published package version 0.5.144 to the npm registry on October 8, 2026. Socket reports that 0.5.144 “contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code.” That release is no longer available for download from the npm package registry.

How the compromised tensorlake 0.5.144 operated

The malicious release added a preinstall hook designed to launch a JavaScript bootstrap ("package/lib/setup.mjs"). An obfuscated loader then launches the payload in "package/lib/Math_Symbol.js" using the Bun runtime. The payload behaves as a credential-stealing, self-propagating worm: it harvests credentials across local files, CI environments, Kubernetes, and HashiCorp Vault; drops a HackBrowserData binary; exfiltrates the collected data; establishes persistence on the host; and facilitates execution of remotely supplied code.

Socket warned that the combined behavior “extends the risk beyond a single stolen API key. Any secrets accessible to the executing process may be exposed, and persistence can retain attacker access after the affected dependency is removed.”

Data targeted and what was stolen

Socket’s analysis lists a broad set of credentials and secrets targeted by the malware. The types of data stolen include npm tokens, GitHub tokens, Amazon Web Services (AWS) credentials and secrets, HashiCorp Vault entries, Kubernetes credentials, SSH keys, .env files, cryptocurrency wallets, messaging app data, and configuration and MCP files associated with Anthropic Claude, Cursor, Kiro, Windsurf, and Zed.

Propagation mechanics: republishing, GitHub workflows, and tooling hooks

To spread, the worm enumerates packages associated with the victim’s publishing identity, builds Sigstore provenance, and republishes compromised versions. Socket noted strings referencing a fake Copilot/Dependabot workflow that suggest the malware also plants GitHub Actions workflows. StepSecurity’s Ashish Kurmi added that the malware “writes .claude/settings.json and .vscode/tasks.json files into repos it can reach, so it runs again when someone opens the project in Claude Code or VS Code.” These files are used to ensure the malicious code will execute again when a developer opens the project in those tools.

Command-and-control, fallback channels, and the “hostage token”

The malware resolves its command-and-control (C2) endpoint using an Ethereum contract, which points to iseekaigogo[.]com. GitHub serves as a fallback mechanism: the adversary stages encrypted stolen data in a public repository whose description reads "Shai-Hulud: Here We Go Again." A separate “hostage token” component implements a PowerShell monitor that repeatedly polls api.github.com/user using the stolen GitHub token to check whether the token remains valid.

Should the victim revoke the stolen token, the monitor executes an attacker-supplied handler through the PowerShell Invoke-Expression cmdlet. The source notes this behavior is designed to “likely trigger a destructive routine,” a tactic observed in earlier Shai-Hulud waves.

What this means for maintainers, security teams, and end users

  • Maintainers: inspect repositories for unexpected commits, check release workflows and provenance, and look for newly written .claude/settings.json and .vscode/tasks.json files that could reinvoke malware when projects are opened.
  • Security teams and DevOps: prioritize scanning for signs of the Math_Symbol.js payload, Bun-based bootstrap code, and the HackBrowserData binary; search logs and artifacts for exfiltration to iseekaigogo[.]com or for staging activity in public GitHub repositories titled “Shai-Hulud: Here We Go Again.”
  • End users and developers who installed tensorlake 0.5.144: remove the malicious package immediately and rotate any exposed credentials, including npm tokens, GitHub tokens, AWS keys, Vault secrets, Kubernetes credentials, SSH keys, .env secrets, and cryptocurrency wallets.

The incident ties back to the ChainDrop/Shai-Hulud campaign first documented in early August 2026, which earlier compromised hundreds of npm packages with Mini Shai-Hulud variants. This wave extends that supply-chain technique into AI agent infrastructure, demonstrating the same blend of obfuscation, persistence, and multi-channel exfiltration used in prior attacks. The immediate, concrete actions are clear in the reporting: remove the malicious package and rotate credentials; the broader question left by the record is how many consumers of tensorlake installed 0.5.144 before it was removed and what lingering persistence artifacts remain in affected environments.

Source: The Hacker News — Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm