tensorlake 0.5.144: npm worm steals cloud and AI-tool credentials
ChainDrop Shai-Hulud preinstall hook on the Tensorlake npm SDK

tensorlake 0.5.144: npm worm steals cloud and AI-tool credentials

The npm package tensorlake, an SDK for Tensorlake's AI agent sandboxes, published version 0.5.144 with a ChainDrop / Shai-Hulud credential worm. Socket flagged the release about 11 minutes after it appeared on 8 October 2026 at 01:12 UTC. You do not have to import the SDK. The install script is enough.

What happened

The release manifest carries a preinstall hook that runs node lib/setup.mjs. Where lifecycle scripts are allowed, that loader uses Bun to launch an obfuscated payload. The payload harvests npm and GitHub tokens, AWS secrets, Vault and Kubernetes credentials, SSH keys, .env files, wallet data, and config for Claude, Cursor, Kiro, Windsurf, and Zed.

It then looks for other packages the victim can publish, builds Sigstore provenance, and republishes poisoned versions. Command and control is not a fixed domain. The worm resolves its endpoint through an Ethereum contract, with a GitHub fallback. A scheduled task polls whether the stolen GitHub token is still valid and runs an attacker-supplied handler if it is revoked. Earlier waves of this family included a string threatening to wipe the home directory on revocation.

Who is affected

Anyone who installed tensorlake@0.5.144, and any build runner that pulled it, should be treated as compromised. The package sees about 12,000 weekly downloads overall. That figure is not a count of malicious installs. The risk is concentrated in developer laptops and CI jobs that still allow dependency lifecycle scripts.

  • Hosts whose lockfile, manifest, or build log shows tensorlake@0.5.144
  • CI runners that execute npm preinstall scripts
  • Machines with cloud, GitHub, npm, or AI-coding credentials in the user or runner profile

What to do now

Remove the persistence before you revoke the token. Socket's guidance is to delete the gh-token-monitor scheduled task first, isolate the host, then rotate npm, GitHub, cloud, and AI-tool credentials from a clean machine. Block 0.5.144, rebuild from a known-good lockfile, and do not assume uninstalling the package removes the implant.

Source: TechNadu, reporting Socket's detection, Tensorlake npm SDK 0.5.144 compromised in ChainDrop attack.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

tensorlake 0.5.144 npm worm steals cloud and AI-tool secrets
Shai-Hulud supply-chain malware in the Tensorlake npm package