Security firms Socket and StepSecurity have reported that version 0.5.144 of the tensorlake npm package, a TypeScript SDK, was compromised to deliver the Shai-Hulud credential-stealing worm to developers and build systems.
The first malicious commit appeared on October 7 at 01:20 UTC. A malicious release reached npm on October 8, and the package has since been removed.
What the Tensorlake Malware Steals and How It Spreads
According to the analysis, the obfuscated malware harvests npm, GitHub and AWS tokens, SSH keys, .env files and cryptocurrency wallet data. It collects them from local files, CI environments, Kubernetes and Vault.
Beyond theft, the code establishes persistence on the infected machine and enables remote code execution. It also spreads on its own by using the victim’s publishing identity, which lets it push malicious versions of other packages that the victim maintains.
Delivery Through Bun and Preinstall Hooks
The malware is delivered through the Bun runtime and through preinstall hooks, which run automatically when a package is installed. A developer or CI job that installs the affected version therefore executes the malicious code without any further action.
The Hostage Token Component
The most unusual capability the researchers describe is a “hostage token” component. It uses PowerShell to watch stolen GitHub tokens, and if a token is revoked, it runs destructive routines.
This design changes the usual response to a credential theft. Revoking a stolen token is normally the first step, and here the revocation itself triggers damage. The researchers’ guidance on credential rotation is therefore qualified: the secrets must be rotated, but carefully, given this behavior.
Part of the ChainDrop and Shai-Hulud Campaign
Socket and StepSecurity link the compromise to the ChainDrop and Shai-Hulud campaign, which they say targets AI infrastructure. Tensorlake is a package aimed at that area. The analysis does not describe how the attackers obtained the ability to publish to the package.
Timeline and Package Removal
The sequence is short. The malicious commit landed early on October 7, the release followed on October 8, and the package was removed from npm the same day, according to the reports. The window in which version 0.5.144 was available to install was therefore brief, though the reports do not say how many installations occurred.
Guidance for Affected Developers
Developers and CI systems that installed version 0.5.144 should treat all of their secrets as exposed. Because of the hostage-token behavior, rotating credentials has to be done with care so that revocation does not set off the destructive routines. The researchers’ reports do not lay out a step-by-step order for doing so.
The first malicious commit and the release on npm were separated by roughly a day. StepSecurity and Socket both analyzed the package, and their reports describe the code as obfuscated, which slows reading of what it does. The reports tie the incident to a campaign aimed at AI infrastructure, and the package belongs to that area of the ecosystem.
Why Self-Propagation Raises the Stakes
A worm that spreads through a victim’s publishing identity turns each infected maintainer into a new distribution point. The malware does not depend on the original attackers compromising packages one by one. An infected developer’s own packages can carry the code onward to their users.
The tensorlake incident also shows the reach of preinstall hooks, which execute before any code review a developer might do on the package contents. Environments that hold many secrets at once, including CI systems with access to npm, GitHub, AWS, Kubernetes and Vault, present the attackers with a large payoff from a single installation.
Organizations that use tensorlake can check their lockfiles and CI logs for version 0.5.144 to determine whether they installed the compromised release.
