Compromised Tensorlake SDK Release Delivers Shai-Hulud Worm

The npm package tensorlake, a TypeScript SDK for Tensorlake applications, sandboxes and cloud services, was compromised to distribute the Shai-Hulud credential-stealing worm. The malicious release, version 0.5.144, was published to npm after rogue files were committed to the tensorlakeai/tensorlake repository; it is no longer available from the registry.
Socket said the release contained obfuscated malware capable of harvesting credentials, exfiltrating secrets, establishing persistence and executing remotely supplied code. StepSecurity reported that the first rogue commit reached the main branch on October 7, 2026, at 01:20 UTC, and the repository release workflow published version 0.5.144 the following day.
Preinstall hook launches the malware chain
Analysis identified a preinstall hook that launches package/lib/setup.mjs. That obfuscated loader starts the main credential-stealing and self-propagating payload, package/lib/Math_Symbol.js, through the Bun runtime.
The stealer searches local files, CI environments, Kubernetes and HashiCorp Vault sources for credentials. It also drops the HackBrowserData binary, sends collected data out of the environment, creates persistence and enables execution of code supplied remotely. Socket warned that the impact can extend beyond a single exposed API key because any secret accessible to the process may be at risk, including after the affected dependency is removed.
Tokens, cloud credentials and developer data are targets
The malware is designed to collect npm and GitHub tokens, AWS credentials and secrets, Vault and Kubernetes credentials, SSH keys, .env files, cryptocurrency wallets, messaging-app data, and configuration or MCP files related to Anthropic Claude, Cursor, Kiro, Windsurf and Zed.
Its propagation logic enumerates packages associated with the victim’s publishing identity, builds Sigstore provenance and republishes compromised package versions. Socket also identified strings referring to a fake Copilot or Dependabot workflow, indicating that the malware may plant GitHub Actions workflows.
The command-and-control endpoint is resolved through an Ethereum contract and uses iseekaigogo[.]com. GitHub can serve as a fallback staging mechanism for encrypted stolen data in a public repository described as “Shai-Hulud: Here We Go Again.”
Revocation monitoring increases the recovery risk
A hostage-token component uses a PowerShell monitor to repeatedly query api.github.com/user with a stolen GitHub token. If a victim revokes that token, the monitor can invoke an attacker-supplied handler via Invoke-Expression, a technique StepSecurity linked to destructive routines seen in earlier Shai-Hulud waves.
The malware can also write .claude/settings.json and .vscode/tasks.json into repositories it can access, allowing code to run again when a project is opened in Claude Code or VS Code. ChainDrop was documented in early August 2026 after hundreds of npm packages, including Keyv and Cacheable, were compromised with a Mini Shai-Hulud variant.
Organizations that installed version 0.5.144 should remove it immediately, rotate credentials accessible to affected developer and CI environments, and examine publishing identities, repository workflows and package releases for signs that the worm propagated further.

