BREAKING · SUPPLY CHAIN / AI AGENTS

tensorlake@0.5.144 is a Shai-Hulud worm. Revoking the stolen GitHub token before you kill the monitor wipes your home directory

On Oct 8 Socket flagged malicious npm version tensorlake@0.5.144 — the TypeScript SDK for Tensorlake’s AI agent serverless sandboxes — as a Shai-Hulud / ChainDrop worm. A preinstall hook runs node lib/setup.mjs on install with no import required. Confirmed victim orgs and infection count: Undisclosed. Company response from Tensorlake: Undisclosed in the sources we reviewed.

Oct 8, 2026 · 3 min read

What shipped and when. Socket says tensorlake@0.5.144 hit npm on Oct 8, 2026 at 01:12:07 UTC and was flagged about 11 minutes later (01:23:10 UTC). The package sits at roughly 12K weekly downloads on npm and the GitHub repo has 1k+ stars — treat those as popularity signals, not confirmed infection counts. Aikido puts lifetime installs for the package (not this version) over 100,000. Malicious files called out by researchers: lib/setup.mjs (SHA256 25a0735d0db7dc40e5d45ce42d9c106067e6a66e184d967cfecfab17c3bcb5ef) and lib/Math_Symbol.js (SHA256 b50a00900399ba99fb6ce1fc151519cb99d44320ef2a631f2237e1aea0ad6fec). StepSecurity notes the preinstall skips CI, so developer machines are the target, and when they checked, 0.5.144 was still downloadable. Pin to 0.5.143.

How the repo got owned. Researchers say malicious commits were pushed directly to tensorlakeai/tensorlake main under a maintainer identity starting around 01:20 UTC on Oct 7 — the GitHub repo was compromised roughly 20 hours before the npm publish. The release carries valid npm provenance. That attestation proves the package came from the repo’s CI path; it does not mean the package is safe once the repo itself is compromised.

What it steals and how it spreads. The worm harvests npm and GitHub tokens, AWS credentials (including IMDS, Secrets Manager, SSM), Vault, Kubernetes secrets, SSH keys, .env files, browser stores, and AI tool configs (.claude, .cursor, Windsurf, and similar). With stolen npm tokens it republishes victim packages. With stolen GitHub tokens it plants .claude / .vscode files and uses a fake author of claude@users.noreply.github.com. Compromised GitHub repos get the description “Shai-Hulud: Here We Go Again.” Researchers report C2 via an Ethereum contract and iseekaigogo.com (Aikido cites the domain plus an Ethereum contract dead-drop; Socket describes endpoint resolution through an Ethereum contract across ~30 RPCs with a GitHub fallback). Aikido saw no sign of compromise on PyPI or Cargo at time of writing.

The hostage move you cannot ignore. A gh-token-monitor keeps polling the stolen GitHub token. If that token is revoked, the malware wipes the home directory — rm -rf ~/ on Unix, Windows profile wipe on Windows. Remove the monitor before you revoke tokens. That sequencing is the difference between containing the theft and deleting the machine.

What we still don’t know. Confirmed victim organizations: Undisclosed. Infection count for 0.5.144 specifically: Undisclosed. Tensorlake’s public response: Undisclosed in Socket, StepSecurity, and Aikido write-ups reviewed for this desk note.

Desk sheet: tensorlake@0.5.144; npm publish Oct 8 01:12:07 UTC; Socket flag 01:23:10 UTC; Shai-Hulud / ChainDrop; preinstall node lib/setup.mjs; repo compromise ~20h earlier on tensorlakeai/tensorlake; valid npm provenance ≠ safe; pin 0.5.143; kill gh-token-monitor before revoking GitHub tokens; C2 via Ethereum contract / isekaigogo.com; PyPI/Cargo clear per Aikido; victim orgs Undisclosed.

Sources