Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
The Shai-Hulud worm has compromised the npm package tensorlake@0.5.144, published on October 8, 2026, turning a TypeScript SDK for agentic AI platforms into a supply-chain infection vector. The malicious version, distributed with a valid provenance attestation through the project's GitHub Actions pipeline, exploits the package installation itself — outside the sandbox the platform is built to provide — to steal multi-layer credentials and self-propagate via victim repositories.
- The tensorlake npm package version 0.5.144, with approximately 12,000 weekly downloads, was published on October 7, 2026 at 01:20 UTC via a compromised maintainer account and removed from npm after Socket detection 11 minutes post-publication.
- The payload activates via a preinstall hook that runs lib/setup.mjs, an obfuscated loader that launches the main worm lib/Math_Symbol.js (~856 KB) using the Bun runtime.
- The malware steals AWS credentials, GitHub tokens, SSH keys, crypto wallets, Kubernetes and Vault configurations, and access files for AI tools (Claude, Cursor, Kiro, Windsurf, Zed), with editor-specific persistence that survives package removal.
- The "hostage token" component monitors GitHub token revocation every 60 seconds and triggers local data destruction, making standard incident response potentially counterproductive.
How the Malware Gets In: The npm Trust Chain Under Attack
The attack began with a push of malicious files to the main branch of the tensorlakeai/tensorlake repository under the name of a legitimate maintainer. According to StepSecurity, the first malicious commit was made on October 7, 2026 at 01:20 UTC. The release workflow then published version 0.5.144 to npm the following day, October 8, 2026 at 01:12 UTC, with a valid provenance attestation — a cryptographic signing mechanism that, in this case, guaranteed the authenticity of the build process without guaranteeing the safety of the code produced.
Socket detected the anomaly 11 minutes after publication. Within that window, the package began to be installed by users and automated systems. The entry vector is the npm preinstall hook: a package.json field that executes lib/setup.mjs during installation. This module, obfuscated, loads the main payload lib/Math_Symbol.js — a file of roughly 856 KB — and executes it via the Bun runtime, designed for high performance but here employed to evade checks based on standard Node.js.
What It Steals and Where It Goes: Multi-Layer Theft and Ethereum C2
The worm implements a sweeping infostealer. According to Socket's analysis, it steals AWS credentials, GitHub tokens, SSH keys, Kubernetes and HashiCorp Vault credentials, cryptocurrency wallets, and browser-saved passwords. But the most insidious targeting concerns AI tool configurations: MCP (Model Context Protocol) files for Claude, Cursor, Kiro, Windsurf, and Zed. These files often contain endpoints and credentials for external AI services, a treasure trove for lateral propagation in enterprise environments.
Command and control (C2) resolves via an Ethereum smart contract at address 0xb614155Fd88114d40549b259457Bcf921Df091B9. According to Endor Labs and OX Security, the contract resolves the domain iseekaigogo[.]com; stolen data is also staged on GitHub as a fallback. The associated Ethereum wallet held approximately $12.44 and had been created 16 days before the attack — a detail that, combined with new encryption public keys relative to previous variants, suggests a different operator from the original TeamPCP group, whose members were arrested in August 2026.
"Teams may isolate an agent's generated code while installing its SDK on a developer workstation, application server, or build runner with access to deployment credentials and other secrets. Code executed during that installation inherits the permissions of the installing process." — Socket, reported by The Register
The Hostage Token: When Incident Response Becomes the Trigger
The most disturbing mechanism is what StepSecurity calls the "hostage token." The malware installs a gh-token-monitor service that checks the validity of the stolen GitHub token every 60 seconds for up to 24 hours. If the token is revoked — the standard incident response practice — the service executes rm -rf ~/ on Unix systems or the Windows equivalent.
The kill-switch string, identical to the one in the TanStack attack of May 2026 — "IfYouRevokeThisTokenItWillWipeTheComputerOfTheOwner" — is confirmed by OX Security. This continuity suggests code sharing or direct inspiration, but the new public keys indicate a different actor or copycat. The practical result is operational paralysis: token revocation, a fundamental corrective action, becomes potentially destructive. According to OX Security, "Shai-Hulud is yet again attacking AI and agentic frameworks, and in an ironic turn of events, a Sandbox for AI, the type of package that's trying to prevent attacks and malwares like Shai-Hulud spreading in the wild."
AI Editor Persistence: The Malware That Survives Cleanup
Persistence extends beyond the operating system. According to Ashish Kurmi of StepSecurity, "The malware also writes .claude/settings.json and .vscode/tasks.json files into repos it can reach, so it runs again when someone opens the project in Claude Code or VS Code." This mechanism turns every accessible repository into a potential reinfection vehicle: even after removal of the npm package and system cleanup, opening the project in an AI editor reactivates the payload.
Self-propagation completes the picture. The worm enumerates npm packages published by the victim, constructs falsified Sigstore provenance, and republishes compromised versions. According to Socket, "That combination extends the risk beyond a single stolen API key. Any secrets accessible to the executing process may be exposed, and persistence can retain attacker access after the affected dependency is removed." Five GitHub repositories with exposed stolen credentials have been identified, according to OX Security.
What to Do Now
- Isolate AI SDK installation: install npm packages in dedicated environments without access to production or deployment credentials, breaking the chain of permissions inherited from the installation process.
- Verify provenance but don't trust it blindly: the valid provenance attestation of tensorlake@0.5.144 proves that build-process signing does not equal code safety: demand independent content audit.
- Check AI editor configurations: inspect .claude/settings.json and .vscode/tasks.json files in repositories to detect persistence masked as legitimate configurations.
- Plan token revocation with hostage-mechanism awareness: before revoking compromised GitHub tokens, evaluate machine isolation to prevent activation of the data-destruction kill-switch.
The AI Sandbox Paradox and the Limits of Defense
The Tensorlake case exposes a structural paradox of agentic AI platforms. Tensorlake is designed to run untrusted code in isolated sandboxes, but the SDK itself — the bridge between developer and platform — installs with full privileges outside any containment. The malware did not "bypass" the sandbox: it struck before the sandbox came into play, during the installation phase that every user must necessarily execute with trust.
Operator identity remains uncertain. The TeamPCP arrests in August 2026 did not stop the threat; new public keys and a young Ethereum wallet indicate an actor who learned from previous mistakes or operates independently. No infrastructure overlaps linking the actor to the original group have emerged to date. The hostage token mechanism, in particular, represents a tactical evolution: it turns security best practice into a vulnerability, forcing victims to choose between continued exposure and immediate destruction.
The dossier does not specify how the maintainer account was compromised, nor how many installations of version 0.5.144 occurred before removal. It is not confirmed that the data-destruction mechanism has been triggered in the wild. Version 0.5.143 is confirmed clean; 0.5.144 has been removed from the npm registry.
Information verified against cited sources and current as of publication.
Sources
- https://www.theregister.com/security/2026/10/08/shai-hulud-worm-makes-jump-to-ai-infrastructure-with-tensorlake-compromise/5302054
- https://thehackernews.com/2026/10/tensorlake-npm-package-compromised-to.html
- https://www.endorlabs.com/learn/tensorlake-npm-package-compromised-by-shai-hulud-in-latest-software-supply-chain-attack
- https://www.ox.security/blog/shai-hulud-here-we-go-again-tensorlake-npm-package-hit-with-malware/
- https://news.lavx.hu/article/hackers-poison-tensorlake-npm-package-to-spread-shai-hulud-credential-stealing-worm
- https://www.stepsecurity.io/blog/tensorlake-npm-compromised-hostage-token-worm
- https://www.stepsecurity.io/
- https://thehackernews.com/
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.