Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm
- ID
- 33111
- Status
- summarized
- Published
- 08 Oct 2026, 1:46 PM
- Fetched
- 08 Oct 2026, 3:48 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/10/tensorlake-npm-package-compromised-to.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 8.5
- Created
- 08 Oct 2026, 3:50 PM
- Tags
- Audience
- developersvibe_codersai_agent_userssaas_startup_founders
What happened
The npm package `tensorlake` (a TypeScript SDK for Tensorlake apps, sandboxes, and cloud services) was compromised in a ChainDrop / Shai-Hulud supply-chain attack; malicious version 0.5.144 has been removed from npm. Its preinstall hook launches `package/lib/setup.mjs`, which loads an obfuscated Bun-based worm (`package/lib/Math_Symbol.js`) that steals npm/GitHub/AWS/Vault/Kubernetes/SSH credentials, `.env` files, crypto wallets, messaging data, and config/MCP files for Claude, Cursor, Kiro, Windsurf, and Zed. It also drops HackBrowserData, persists on hosts, republishes victim-associated packages with Sigstore provenance, may plant GitHub Actions workflows, and resolves C2 via an Ethereum contract with GitHub as fallback.
Why it matters
If your team installed tensorlake v0.5.144 or runs npm installs in CI with broad cloud/Vault/Kubernetes/GitHub tokens, rotate every secret accessible to that process and check for `package/lib/setup.mjs` / `Math_Symbol.js`; removing the dependency alone may not remove persistence. Because it targets MCP and AI coding-agent config files for Claude, Cursor, Kiro, Windsurf, and Zed, treat local agent configs as credential-bearing and review GitHub Actions for fake Copilot/Dependabot workflow injections.
Discussion angle
How would your team detect and contain a preinstall hook that steals CI, Vault, Kubernetes, and AI-agent MCP credentials—and what token scoping would have limited the blast radius?