Tensorlake npm SDK 0.5.144 compromised in a ChainDrop / Shai-Hulud worm attack: installs steal developer and cloud secrets, republish the victim's own packages, and a token monitor wipes the home directory if the stolen GitHub token is revoked
Socket and StepSecurity reported on 8 October 2026 that version 0.5.144 of tensorlake, the TypeScript SDK for Tensorlake's sandboxes for running LLM-generated code (about 12,000 weekly downloads), was malicious. StepSecurity says someone pushed eight commits straight to the main branch of tensorlakeai/tensorlake under a maintainer's name from 01:20 UTC on 7 October, and the project's own release workflow published 0.5.144 to npm at 01:12 UTC on 8 October, so the package carries a genuine npm provenance attestation. Socket flagged it about 11 minutes after release and it has since been pulled from npm. A preinstall hook runs lib/setup.mjs, which skips CI, downloads the Bun runtime and runs an obfuscated payload (lib/Math_Symbol.js) that collects GitHub and npm tokens, cloud keys, Kubernetes and Vault secrets, SSH keys, saved browser logins and config files for AI coding tools. Data goes to a public GitHub repository created in the victim's account (description 'Shai-Hulud: Here We Go Again') or to a server found through an Ethereum contract. With a stolen npm token the worm republishes the victim's packages with itself added; with a GitHub token it commits .claude/settings.json and .vscode/tasks.json files so it runs again when a project is opened in Claude Code or VS Code. It also installs a gh-token-monitor service that checks the stolen token every 60 seconds for up to 24 hours and deletes the user's home directory (or Windows profile) if the token stops working. The loader and payload names match the August ChainDrop compromises of keyv and cacheable. Primary: Socket and StepSecurity; wire: The Hacker News.
- Product
- tensorlake (npm TypeScript SDK for Tensorlake AI agent sandboxes)
- Versions
- 0.5.144 malicious; 0.5.143 is the last clean release named by StepSecurity
- Exploited in Australia?
- unknown
- Patch to
- Search lockfiles, build logs and images for tensorlake@0.5.144 and pin to 0.5.143. On any machine that installed it, remove the gh-token-monitor service first (systemd user unit on Linux, LaunchAgent on macOS, ONLOGON scheduled task on Windows) and only then revoke and rotate GitHub, npm, cloud, Kubernetes, Vault and SSH credentials. Look for new public repositories described 'Shai-Hulud: Here We Go Again', unexpected versions of your own npm packages, and commits adding .claude/settings.json or .vscode/tasks.json with the message 'chore: update dependencies'. Rebuild affected hosts from a clean source, and block install scripts (npm --ignore-scripts) where you can.
Primary: Socket — Tensorlake npm SDK compromised in ChainDrop Shai-Hulud credential-stealing attack (8 Oct 2026) · Vendor: StepSecurity — Tensorlake npm package compromised: a worm with a hostage token (8 Oct 2026) · The Hacker News — Tensorlake npm package compromised to deliver Shai-Hulud credential-stealing worm (8 Oct 2026)
