
Tensorlake npm malware steals secrets and survives removal
Tensorlake npm version 0.5.144 carried a credential-stealing worm that could retain access after removal, putting developer and cloud secrets at risk.
Tensorlake npm version 0.5.144 was compromised to steal credentials and maintain access to affected computers, according to security firm Socket. The package, distributed through npm, a registry for JavaScript software packages, is a TypeScript software development kit that helps developers build applications using Tensorlake applications, sandboxes and cloud services. The malicious release is no longer available from npm, but removing an installed copy may not eliminate the attacker's access.
The Hacker News reports that the compromise belongs to the ChainDrop / Shai-Hulud supply chain attack, which spreads malicious code through software that other developers depend on. Socket identified deliberately obscured code in the release that collects secrets, sends them outside the victim's environment and runs instructions supplied remotely. For businesses and website operators, the relevant exposure is not simply the package itself: it is the access available to the computer or automated build process that ran it.
According to StepSecurity, the malicious files entered the main development branch of the tensorlakeai/tensorlake repository, its shared store of source code, under a maintainer's name. The first malicious commit, a recorded code change, occurred on October 7, 2026, at 01:20 a.m. UTC. The repository's automated release workflow published version 0.5.144 to npm a day later. Attribution of the changes to a maintainer's name does not, by itself, establish who actually made them.
The installation path explains how the Tensorlake npm release could execute its payload. Socket's analysis found a preinstall hook, an instruction run before package installation, that starts package/lib/setup.mjs. This JavaScript file conceals its purpose through obfuscation, code written to be difficult to understand. It then uses Bun, a program for running JavaScript, to launch package/lib/Math_Symbol.js, the main secret-stealing worm. A worm is malware that can spread without someone manually copying it to each new victim.
The collection targets span local files, continuous integration (CI) systems that automate software builds and tests, Kubernetes systems that manage applications, and HashiCorp Vault, a service for storing secrets. Socket lists npm and GitHub access tokens, Amazon Web Services (AWS) credentials and secrets, Kubernetes credentials, SSH keys used for remote access, and .env files that commonly hold application settings and secrets. Cryptocurrency wallets and messaging app data are also targets, along with configuration and Model Context Protocol (MCP) files associated with Anthropic Claude, Cursor, Kiro, Windsurf and Zed. MCP connects artificial intelligence tools to other software and data sources.
The malware also places the HackBrowserData data-extraction tool on the affected computer. Socket says the combination of theft, remote code execution and persistence, mechanisms that allow malicious code to remain active, creates exposure beyond one compromised API key, a secret used to access a service. Any secret the running process can read may be at risk. For an IT team, that means assessing the permissions and stored credentials of the affected environment, rather than assuming that only Tensorlake-related access needs attention.
To spread, the worm identifies packages linked to the victim's publishing account and republishes infected versions, Socket reports. It also generates Sigstore provenance, records intended to document how software was built. References in the code to a bogus Copilot/Dependabot workflow suggest that it additionally plants GitHub Actions workflows, automated tasks hosted on GitHub. That workflow finding is an indication from the code, not a confirmed account of every action taken on affected systems.
For communications, the malware uses an Ethereum contract, code stored on that blockchain, to locate its command-and-control endpoint at iseekaigogo[.]com. This endpoint is the address through which attackers coordinate the malware. GitHub provides a fallback route: encrypted stolen information can be placed in a public repository whose description is "Shai-Hulud: Here We Go Again."
A separate "hostage token" mechanism makes recovery more delicate. A monitor written in PowerShell, Microsoft's command and automation environment, repeatedly checks api.github.com/user with a stolen GitHub token to see whether it still works. If the victim revokes that token, the monitor runs an attacker-provided handler through Invoke-Expression, a command that executes PowerShell code. The source describes this as likely intended to trigger destructive behavior, consistent with a tactic seen in earlier Shai-Hulud waves; it does not establish that destruction occurred in this incident.
StepSecurity researcher Ashish Kurmi identified another way the malware can return. It writes .claude/settings.json and .vscode/tasks.json into repositories it can access, enabling it to run again when a person opens the project in Claude Code or VS Code. These changes help explain why uninstalling the dependency alone is not a complete response: project settings can provide a separate route for execution.
ChainDrop was first documented in early August 2026 after hundreds of npm packages, including Keyv and Cacheable, were compromised. Those packages contained a Mini Shai-Hulud variant, also using an obscured JavaScript payload run through Bun to steal credentials and propagate. The Tensorlake compromise extends that activity into artificial intelligence (AI) agent infrastructure, software used by AI systems that perform tasks, where development tools may have access to business secrets.
For readers seeking help reviewing this kind of development-environment exposure, AEU-I offers security-first IT, infrastructure and consulting services, a relevant source of support rather than a claim of protection against this specific worm. The source advises anyone who installed Tensorlake version 0.5.144 to remove it immediately and replace exposed credentials. Given the reported persistence and token-monitoring behavior, affected businesses should have their IT team coordinate that work with checks for malicious project settings and workflows, rather than treating package removal as proof of recovery.
How to Protect Yourself
- Ask your website developer or IT provider to check whether Tensorlake version 0.5.144 was installed on any computer or system used to build your site.
- If that version is found, have your IT provider remove it and check for malicious project settings before anyone reopens the affected projects.
- Ask your IT provider to coordinate replacement of exposed access keys and account tokens, because this malware may react when stolen GitHub access is cancelled.
- Have the person managing your GitHub account review recent code changes and automated tasks for anything they did not authorize.
Terms Explained
- npm A registry developers use to obtain and publish reusable JavaScript software packages.
- supply chain attack An attack that compromises software people trust so it can reach the people or businesses using it.
- preinstall hook An instruction that automatically runs before a software package is installed.
- continuous integration (CI) An automated process that builds and tests software when developers change it.
- persistence Ways malicious software keeps its ability to run after the original infection.
- access tokens Digital secrets that let software use an account without entering its password each time.
- command-and-control The communication system attackers use to direct malicious software.