The npm package tensorlake, an SDK for Tensorlake's AI agent sandboxes, published version 0.5.144 with a ChainDrop / Shai-Hulud credential worm. Socket flagged the release about 11 minutes after it appeared on 8 October 2026 at 01:12 UTC. You do not have to import the SDK. The install script is enough.
What happened
The release manifest carries a preinstall hook that runs node lib/setup.mjs. Where lifecycle scripts are allowed, that loader uses Bun to launch an obfuscated payload. The payload harvests npm and GitHub tokens, AWS secrets, Vault and Kubernetes credentials, SSH keys, .env files, wallet data, and config for Claude, Cursor, Kiro, Windsurf, and Zed.
It then looks for other packages the victim can publish, builds Sigstore provenance, and republishes poisoned versions. Command and control is not a fixed domain. The worm resolves its endpoint through an Ethereum contract, with a GitHub fallback. A scheduled task polls whether the stolen GitHub token is still valid and runs an attacker-supplied handler if it is revoked. Earlier waves of this family included a string threatening to wipe the home directory on revocation.
Who is affected
Anyone who installed tensorlake@0.5.144, and any build runner that pulled it, should be treated as compromised. The package sees about 12,000 weekly downloads overall. That figure is not a count of malicious installs. The risk is concentrated in developer laptops and CI jobs that still allow dependency lifecycle scripts.
- Hosts whose lockfile, manifest, or build log shows tensorlake@0.5.144
- CI runners that execute npm preinstall scripts
- Machines with cloud, GitHub, npm, or AI-coding credentials in the user or runner profile
What to do now
Remove the persistence before you revoke the token. Socket's guidance is to delete the gh-token-monitor scheduled task first, isolate the host, then rotate npm, GitHub, cloud, and AI-tool credentials from a clean machine. Block 0.5.144, rebuild from a known-good lockfile, and do not assume uninstalling the package removes the implant.
Source: TechNadu, reporting Socket's detection, Tensorlake npm SDK 0.5.144 compromised in ChainDrop attack.
Also on the blog
- CVE-2026-21589: unauthenticated file read on 8 Atlassian products
- FortiBleed: FBI says 86,644 FortiGate devices still locked out
- Chrome 155 patches 247 flaws, four of them critical
- CVE-2026-102255: SonicWall SMA1000 SSRF scores CVSS 10
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.