Tensorlake npm Package Compromised With a Shai-Hulud Worm That Targets AI Tool Configs and Wipes Home Directories If Stolen Tokens Are Revoked
StepSecurity and Socket report that [email protected] on npm steals credentials and AI-tool configs, and installs a monitor that deletes files if a stolen GitHub token is revoked.
Overview
Version 0.5.144 of the tensorlake npm package, a TypeScript SDK for Tensorlake applications, sandboxes and cloud services, was compromised in what The Hacker News describes as a ChainDrop / Shai-Hulud supply chain attack. Socket, quoted by The Hacker News, said the release “contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code.”
StepSecurity, which reported the release to the maintainers in GitHub issue #1014 on October 8, 2026, advises that anyone who installed it should pin tensorlake to 0.5.143 and, importantly, not revoke any tokens until a background monitor is removed.
What We Know
How the release was made
According to StepSecurity, the first malicious commit landed on the main branch at 01:20 UTC on October 7 under a maintainer’s name, and seven more commits followed over the next few hours. StepSecurity says none of them went through a pull request. At 01:12 UTC on October 8, it says, the repository’s release workflow published 0.5.144 to npm.
Because the package was built and released from the project’s own repository, StepSecurity says npm shows a provenance attestation for it. The firm’s wording: “The attestation says where a package was built. It doesn’t say the code is safe.”
What the malware does
Per The Hacker News, the release carries a preinstall hook that launches a JavaScript file, package/lib/setup.mjs, an obfuscated loader that starts the main worm, package/lib/Math_Symbol.js, using the Bun runtime. The stealer targets local files, CI environments, Kubernetes and Vault sources, and drops the HackBrowserData binary. The data it seeks includes npm tokens, GitHub tokens, AWS credentials, SSH keys, .env files, cryptocurrency wallets, and “Configuration and MCP files associated with Anthropic Claude, Cursor, Kiro, Windsurf, and Zed.”
StepSecurity adds that the loader skips itself on CI, so developer machines are the target. Stolen data is encrypted and sent either to a public GitHub repository the malware creates, with the description “Shai-Hulud: Here We Go Again,” or to iseekaigogo.com, according to StepSecurity. The Hacker News reports that the malware uses an Ethereum contract to resolve that command-and-control endpoint.
Spreading through AI tool configuration
With a stolen npm token, StepSecurity says, the malware downloads the victim’s packages, adds itself, bumps the version and republishes them. With a stolen GitHub token, it commits .claude and .vscode files to the victim’s repositories under a fake [email protected] author and the message “chore: update dependencies.” In the words of StepSecurity’s Ashish Kurmi, the malware “writes .claude/settings.json and .vscode/tasks.json files into repos it can reach, so it runs again when someone opens the project in Claude Code or VS Code.”
The hostage token
StepSecurity says that when the malware holds a GitHub token it installs a service called gh-token-monitor, which checks the token against the GitHub API every 60 seconds for up to 24 hours. If GitHub rejects the token, the service runs rm -rf ~/ on Unix-like systems or a PowerShell delete of the user profile on Windows. The Hacker News describes the Windows-side component as a PowerShell monitor that polls api.github.com/user and, if the token is revoked, runs an attacker-supplied handler through the Invoke-Expression cmdlet, likely to trigger a destructive routine, a tactic it says was observed in earlier Shai-Hulud waves.
StepSecurity’s remediation order is to check for 0.5.144 with npm ls tensorlake, pin 0.5.143, remove the token monitor, and only then rotate credentials. It also notes that setting ignore-scripts=true in .npmrc stops install hooks like this one.
What We Don’t Know
The sources differ on availability. The Hacker News reports that version 0.5.144 “is no longer available for download from the npm package registry,” while StepSecurity wrote that when it checked, 0.5.144 could still be downloaded. Neither source gives the number of installs, and neither identifies the attacker or explains how the maintainer’s identity was used to push the commits. The Hacker News notes that Socket’s strings referencing a fake Copilot/Dependabot workflow suggest the worm may also plant GitHub Actions workflows, but that is an inference, not a confirmed behavior.
Context
The Hacker News says ChainDrop was first documented in early August 2026 in connection with the compromise of hundreds of npm packages, including Keyv and Cacheable. The Machine Herald previously reported on that wave. The Hacker News says the Tensorlake incident extends the attack to AI agent infrastructure.
For teams that trust npm provenance as a safety signal, StepSecurity’s account is a caution: the attestation here was valid because the malicious code was committed to the legitimate repository and released through its own workflow.