The npm package `tensorlake`, a TypeScript SDK for Tensorlake apps, sandboxes and cloud services, was compromised in a ChainDrop/Shai-Hulud supply-chain attack. Socket reports that malicious version 0.5.144 contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence and executes remotely supplied code. The version is no longer downloadable from the npm registry. The incident was reported on 8 October 2026 after malicious code was pushed to `tensorlakeai/tensorlake` on 7 October and published via the release workflow the next day.
The infection chain starts with a `preinstall` hook launching `package/lib/setup.mjs`, an obfuscated loader that starts the main worm `package/lib/Math_Symbol.js` via the Bun runtime. The stealer collects npm and GitHub tokens, AWS credentials, HashiCorp Vault, Kubernetes credentials, SSH keys, `.env` files, crypto wallets, messaging data, and config/MCP files tied to Anthropic Claude, Cursor, Kiro, Windsurf and Zed. It also drops the HackBrowserData binary. Persistence means attacker access can survive after the malicious dependency is removed.
To propagate, the worm enumerates packages tied to the victim’s publishing identity, builds Sigstore provenance and republishes compromised versions. Strings referencing a fake Copilot/Dependabot workflow suggest it also plants GitHub Actions. The C2 endpoint (`iseekaigogo.com`) is resolved via an Ethereum contract, with GitHub as a fallback staging stolen encrypted data in public repos described as "Shai-Hulud: Here We Go Again". A PowerShell "hostage token" monitor polls `api.github.com/user` with the stolen GitHub token; if the token is revoked, an `Invoke-Expression` handler can run a destructive routine — seen in earlier Shai-Hulud waves.
StepSecurity traces malicious files pushed to main under a maintainer’s name on 7 October at 01:20 UTC; the release workflow published 0.5.144 on 8 October. The malware also writes `.claude/settings.json` and `.vscode/tasks.json` into reachable repos so it runs again when someone opens the project in Claude Code or VS Code. ChainDrop was documented in August 2026 across hundreds of npm packages (including Keyv and Cacheable) with Mini Shai-Hulud via Bun payloads — the campaign now reaches AI agent infrastructure.
What makes this wave especially dangerous for engineering organisations is that it targets the toolchain around AI agents: cloud tokens, Vault, Kubernetes and IDE/agent configs in one package. A single `npm install` in CI can therefore empty both a cloud account and a local developer laptop. The “hostage token” behaviour — retaliation on revocation — means incident response must coordinate token rotation with endpoint containment, or destructive scripts may fire exactly when responders think they are cleaning up.
Nordic teams using Tensorlake, or mirroring npm packages internally, should check mirrors and lockfiles for 0.5.144, review which pipelines ran `npm ci` between 7 and 8 October UTC, and assume every secret in that environment is burned. Vendor risk is organisational too: a maintainer name on a push is not trust — required review, signed commits and limited publish rights are baseline after Shai-Hulud.
What developers and security leads should do now
If `[email protected]` was installed: remove it immediately, clean `node_modules`/lockfiles, review CI history. Rotate every secret that may have leaked (npm, GitHub, AWS, Vault, K8s, SSH, `.env`, AI tooling). Hunt for unexpected GitHub Actions, `.claude/settings.json`, `.vscode/tasks.json` and Bun-related processes. Audit packages you publish for unauthorised versions. Require 2FA and short-lived tokens for npm/GitHub; restrict which workflows may publish. Isolate developer machines that ran the malicious version until forensics is complete.