The npm package tensorlake, a TypeScript SDK for Tensorlake applications, was compromised on 8 October 2026. Version 0.5.144 carried a Shai-Hulud / ChainDrop worm that steals credentials on install and tries to republish itself through the victim's npm token. npm has removed that version.
What happened
StepSecurity says the malicious files were pushed to the project's main branch under a maintainer identity. The first rogue commit landed at 01:20 UTC on 7 October. The release workflow then published 0.5.144, including an npm provenance attestation, because the build came from the repository itself.
A preinstall hook skips CI and targets developer machines. It downloads the Bun runtime and runs an obfuscated stealer. Socket says the payload harvests npm and GitHub tokens, AWS secrets, Vault and Kubernetes credentials, SSH keys, .env files, crypto wallets, and config for Claude, Cursor, Windsurf, and related AI tools. Stolen data is staged in a public GitHub repo described as "Shai-Hulud: Here We Go Again", or sent to a command server resolved through an Ethereum contract.
A hostage-token monitor polls the stolen GitHub token. If the victim revokes it, the monitor runs attacker-supplied PowerShell, a destructive pattern seen in earlier Shai-Hulud waves. The worm also writes project hooks so it runs again when the repo is opened in Claude Code or VS Code.
Who is affected
- Anyone who installed tensorlake 0.5.144 on a developer workstation
- Teams whose npm or GitHub tokens were present on that machine
- Downstream packages the worm may have republished under a stolen publisher identity
What to do now
Remove 0.5.144, then rotate every token that machine could see: npm, GitHub, cloud, SSH, and AI-tool credentials. Search GitHub for unexpected public repos with the Shai-Hulud description, and check .claude/settings.json and .vscode/tasks.json in repos the machine could write. Do not treat a provenance badge as proof the release is clean.
Source: The Hacker News, Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm.
Also on the blog
- CVE-2026-21589: unauthenticated file read on 8 Atlassian products
- FortiBleed: FBI says 86,644 FortiGate devices still locked out
- CVE-2026-102255: CVSS 10 SSRF in SonicWall SMA1000
- .gh .sl .as registry hijacks minted 12 Google certificates
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.