The npm package tensorlake, the official TypeScript SDK for Tensorlake’s agentic AI platform, was compromised in early October 2026. Version 0.5.144 shipped with an obfuscated credential-stealing worm from the ChainDrop / Shai-Hulud family that runs automatically on install. It harvests npm and GitHub tokens, AWS credentials, Kubernetes and Vault secrets, SSH keys, .env files, crypto wallets, and configuration files for AI coding tools including Claude Code, Cursor, Kiro, Windsurf, and Zed. If you installed version 0.5.144, remove it and rotate every credential that lived on the affected machine.
What happened: the timeline
According to analyses by Socket and StepSecurity, reported by The Hacker News on October 8, 2026:
- October 7, 2026, 1:20 a.m. UTC: the first rogue commit was pushed to the main branch of the tensorlakeai/tensorlake GitHub repository, apparently under a maintainer’s name.
- October 8, 2026: the repository’s release workflow published version 0.5.144 to npm. The malicious version is no longer available for download from the npm registry.
- October 8, 2026: security researchers published technical analyses, and news of the compromise broke. Users who installed the malicious version were advised to remove it immediately and rotate their credentials.
What Tensorlake is and why attackers picked it
Tensorlake is a platform for agentic applications: a document ingestion API that turns PDFs, spreadsheets, and other documents into structured data, plus serverless infrastructure for deploying AI agents and sandboxes. Its SDK users are developers building AI agents and document pipelines.
That is exactly why the package was valuable to attack. The machines of developers working with agentic AI tend to hold cloud credentials, API keys, CI tokens, and configuration files for AI coding assistants. Compromising the official SDK turned a routine npm install into a direct path onto those machines. This is the same reason AI infrastructure keeps getting targeted: we have previously covered how the GitLab AI Gateway flaw let an authenticated user run arbitrary commands on self-managed AI infrastructure, and how a KVM zero-day broke out of virtual machines running AI workloads. Attackers follow where the valuable secrets live.
How the worm works
The preinstall hook
The compromised release hides its payload in the package’s install lifecycle. Installing version 0.5.144 triggers a preinstall hook that launches package/lib/setup.mjs, an obfuscated loader. That loader starts the main worm, package/lib/Math_Symbol.js, using the Bun runtime. Because preinstall hooks run automatically, victims do not need to execute any code themselves; simply adding the dependency is enough.
The credential stealer
The worm sweeps the machine for secrets across local files, CI environments, Kubernetes clusters, and Vault sources. It also drops the HackBrowserData binary to extract credentials stored in web browsers. Once collected, the data is exfiltrated, persistence is established on the host, and the malware can execute remotely supplied code.
Socket warned that this combination extends the risk well beyond a single stolen API key: any secret accessible to the installing process may be exposed, and the persistence mechanism can keep attackers in place even after the affected dependency is removed.
What data it steals
The confirmed list of targeted data includes:
- npm tokens
- GitHub tokens
- Amazon Web Services (AWS) credentials and secrets
- HashiCorp Vault secrets
- Kubernetes credentials
- SSH keys
- .env files
- Cryptocurrency wallets
- Messaging app data
- Configuration and MCP files for Anthropic Claude, Cursor, Kiro, Windsurf, and Zed
That last item is notable. The worm deliberately collects configuration and MCP (Model Context Protocol) files from the most popular AI coding tools, which often contain API keys and connection credentials for agents that can act on a developer’s behalf.
How the worm spreads itself
Shai-Hulud is self-propagating, which is what makes this incident larger than a single package:
- It republishes your packages. The worm enumerates packages associated with the victim’s npm publishing identity, builds Sigstore provenance, and republishes compromised versions of those packages. If you maintain npm packages and installed the bad version, your own packages may now carry the worm.
- It plants CI workflows. Strings referencing a fake Copilot/Dependabot workflow found in the malware suggest it also plants malicious GitHub Actions workflows in repositories it can reach.
- It reinfects through your editor. According to StepSecurity’s Ashish Kurmi, the malware writes
.claude/settings.jsonand.vscode/tasks.jsonfiles into repositories it can access, so it runs again whenever someone opens the project in Claude Code or VS Code. - It uses unusual command and control. The malware resolves its command-and-control endpoint (
iseekaigogo[.]com) through an Ethereum smart contract, with GitHub as a fallback: stolen data is staged in a public repository described as “Shai-Hulud: Here We Go Again.”
The “hostage token” retaliation trick
One of the nastiest components is the “hostage token” monitor. It uses a PowerShell process to repeatedly poll api.github.com/user with the stolen GitHub token, checking whether the token is still valid. If the victim revokes the token, the monitor executes an attacker-supplied handler through PowerShell’s Invoke-Expression, which researchers assess is designed to trigger a destructive routine. This behavior was observed in earlier Shai-Hulud waves.
The practical consequence: simply revoking a token on a still-infected machine can backfire. Credential rotation has to be paired with full machine remediation, and ideally done from a clean system.
What to do if you installed version 0.5.144
- Remove the package from your projects and lockfiles, and confirm no other dependency pulls in the compromised version.
- Treat the machine as compromised. Assume everything it could reach is exposed: npm and GitHub tokens, AWS keys, Vault and Kubernetes credentials, SSH keys, API keys in .env files, browser-stored credentials, and crypto wallet keys.
- Remediate the host first. Because persistence can survive dependency removal, wipe or rebuild the machine (or restore from a known-clean image) before generating replacement credentials.
- Rotate every credential from a clean system: npm tokens, GitHub tokens, AWS access keys, Vault/Kubernetes secrets, SSH keys, database passwords, and anything stored in the browser.
- Check your repositories for planted
.claude/settings.jsonand.vscode/tasks.jsonfiles, unknown GitHub Actions workflows, and the rogue commit in your projects. - Check your npm publish history. If you have an npm publishing identity, verify that no versions you did not author were published, and check Sigstore provenance for anything unauthorized. If unauthorized versions went out, deprecate and republish from a clean machine.
The bigger picture: Shai-Hulud keeps coming back
This is not the first Shai-Hulud wave. The ChainDrop campaign was first documented in early August 2026, when hundreds of npm packages, including widely used ones like Keyv and Cacheable, were found carrying a Mini Shai-Hulud variant delivered through an obfuscated Bun-based JavaScript payload. The October attack on Tensorlake extends the campaign into AI agent infrastructure.
The pattern is clear: supply chain attackers are moving up the stack to the tools developers trust most. AI agents are both the target and, increasingly, the vector. That is why we have seen AI security become a front-line topic this year, from Google’s PageBreak AI agent finding more than 500 XSS vulnerabilities on the defensive side, to prompt-sandbox escapes on the offensive one. For developers, the lesson is uncomfortable but simple: the install step of your package manager is now one of the most dangerous moments in your workflow.
Frequently asked questions
Which version of tensorlake was compromised?
Only version 0.5.144. It was published to npm around October 8, 2026, after a rogue commit on October 7, and has since been removed from the registry. Check your lockfiles with npm ls tensorlake to see which version you have.
I installed tensorlake months ago. Am I affected?
No, unless you updated to 0.5.144 during the short window it was available. Earlier versions are not part of this incident.
Is the malicious version still downloadable?
No. Version 0.5.144 has been removed from the npm registry. But copies may still exist in build caches, Docker layers, and vendored dependencies, so scan your pipelines.
Can I just delete the package and move on?
No. The worm exfiltrates credentials and establishes persistence, and deleting the dependency does not remove the persistence or un-steal the credentials. Follow the full remediation steps above: rebuild the host, rotate everything, and audit your repos and npm publishes.
What is ChainDrop / Shai-Hulud?
It is a family of self-propagating npm supply chain attacks. The first large wave hit in August 2026 with hundreds of compromised packages. The campaign gets its name from the public repository used to stage stolen data, described as “Shai-Hulud: Here We Go Again.” The October 2026 Tensorlake compromise is the latest wave.
How do I protect my team from npm supply chain attacks?
Pin and lock dependency versions, review diffs before updating packages, verify Sigstore provenance on critical installs, use least-privilege and short-lived tokens, keep publishing credentials off developer workstations, and run package-scanning tools (like Socket) in your CI pipeline so a malicious version gets flagged before it reaches production.
