tensorlake 0.5.144 npm worm steals cloud and AI-tool secrets
Shai-Hulud supply-chain malware in the Tensorlake npm package

tensorlake 0.5.144 npm worm steals cloud and AI-tool secrets

The npm package tensorlake, a TypeScript SDK for Tensorlake applications, was compromised on 8 October 2026. Version 0.5.144 carried a Shai-Hulud / ChainDrop worm that steals credentials on install and tries to republish itself through the victim's npm token. npm has removed that version.

What happened

StepSecurity says the malicious files were pushed to the project's main branch under a maintainer identity. The first rogue commit landed at 01:20 UTC on 7 October. The release workflow then published 0.5.144, including an npm provenance attestation, because the build came from the repository itself.

A preinstall hook skips CI and targets developer machines. It downloads the Bun runtime and runs an obfuscated stealer. Socket says the payload harvests npm and GitHub tokens, AWS secrets, Vault and Kubernetes credentials, SSH keys, .env files, crypto wallets, and config for Claude, Cursor, Windsurf, and related AI tools. Stolen data is staged in a public GitHub repo described as "Shai-Hulud: Here We Go Again", or sent to a command server resolved through an Ethereum contract.

A hostage-token monitor polls the stolen GitHub token. If the victim revokes it, the monitor runs attacker-supplied PowerShell, a destructive pattern seen in earlier Shai-Hulud waves. The worm also writes project hooks so it runs again when the repo is opened in Claude Code or VS Code.

Who is affected

  • Anyone who installed tensorlake 0.5.144 on a developer workstation
  • Teams whose npm or GitHub tokens were present on that machine
  • Downstream packages the worm may have republished under a stolen publisher identity

What to do now

Remove 0.5.144, then rotate every token that machine could see: npm, GitHub, cloud, SSH, and AI-tool credentials. Search GitHub for unexpected public repos with the Shai-Hulud description, and check .claude/settings.json and .vscode/tasks.json in repos the machine could write. Do not treat a provenance badge as proof the release is clean.

Source: The Hacker News, Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

FortiBleed: FBI says 86,644 FortiGate devices still locked out
Ongoing credential reuse against FortiGate firewalls and SSL VPN gateways