AI Weekly Malaysia

Back to items Summaries

Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm

ID
33111
Status
summarized
Published
08 Oct 2026, 1:46 PM
Fetched
08 Oct 2026, 3:48 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/10/tensorlake-npm-package-compromised-to.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
8.5
Created
08 Oct 2026, 3:50 PM
Tags
Audience
developersvibe_codersai_agent_userssaas_startup_founders

What happened

The npm package `tensorlake` (a TypeScript SDK for Tensorlake apps, sandboxes, and cloud services) was compromised in a ChainDrop / Shai-Hulud supply-chain attack; malicious version 0.5.144 has been removed from npm. Its preinstall hook launches `package/lib/setup.mjs`, which loads an obfuscated Bun-based worm (`package/lib/Math_Symbol.js`) that steals npm/GitHub/AWS/Vault/Kubernetes/SSH credentials, `.env` files, crypto wallets, messaging data, and config/MCP files for Claude, Cursor, Kiro, Windsurf, and Zed. It also drops HackBrowserData, persists on hosts, republishes victim-associated packages with Sigstore provenance, may plant GitHub Actions workflows, and resolves C2 via an Ethereum contract with GitHub as fallback.

Why it matters

If your team installed tensorlake v0.5.144 or runs npm installs in CI with broad cloud/Vault/Kubernetes/GitHub tokens, rotate every secret accessible to that process and check for `package/lib/setup.mjs` / `Math_Symbol.js`; removing the dependency alone may not remove persistence. Because it targets MCP and AI coding-agent config files for Claude, Cursor, Kiro, Windsurf, and Zed, treat local agent configs as credential-bearing and review GitHub Actions for fake Copilot/Dependabot workflow injections.

Discussion angle

How would your team detect and contain a preinstall hook that steals CI, Vault, Kubernetes, and AI-agent MCP credentials—and what token scoping would have limited the blast radius?

Top