Tensorlake: Tensorlake npm Package Compromised to Spread Shai-Hulud Worm and Steal Developer Secrets

Tensorlake: Tensorlake npm Package Compromised to Spread Shai-Hulud Worm and Steal Developer Secrets

Malicious Tensorlake npm Package Distributes Shai-Hulud Worm in Supply Chain Attack

On October 8, 2026, a compromised version of the Tensorlake npm package (v0.5.144) was published, containing a Shai-Hulud worm variant designed to steal developer secrets and propagate through software supply chains. Tensorlake, a serverless sandbox platform for AI agents, has over 100,000 lifetime installs, amplifying the potential impact of the breach.

The attack was discovered by Aikido Security, which confirmed that only the npm distribution was affected PyPI and Cargo versions showed no signs of compromise. The malware activates during installation, executing before developers interact with the package, eliminating the need for user interaction like phishing or malicious links.

The infection follows a pattern seen in recent Shai-Hulud worm campaigns, where stolen package publishing credentials enable lateral movement across development environments, CI/CD pipelines, and cloud systems. Aikido’s analysis revealed a unique global WORMTAG marker in the payload, indicating a fresh compromise rather than a reinfection from prior attacks.

The attack originated from a malicious GitHub commit (41b38f0) on October 7, where an actor used a verified maintainer identity to upload the payload. The repository remained compromised for 20 hours before the malicious npm release was published.

Malware Execution & Data Theft

The infection begins with a preinstall script (node lib/setup.mjs), which is heavily obfuscated and downloads the Bun JavaScript runtime a tactic used to evade security tools that focus on Node.js activity. The script then executes lib/Math_Symbol.js, containing the Shai-Hulud payload.

Once active, the malware targets:

  • Environment variables (AWS, Kubernetes, Azure, Docker, GitHub Copilot)
  • Local credential files (SSH, Vault tokens, CI/CD systems)
  • Browser profiles (MetaMask, Phantom, Coinbase Wallet, Trust Wallet, and 10+ other crypto wallets)

The broader focus on cryptocurrency wallets suggests the attackers may be seeking quick monetization alongside credential theft for further supply chain attacks.

Command-and-Control & Evasion Tactics

The malware uses a hardcoded C2 domain (iseekaigogo[.]com) but can also retrieve an alternate exfiltration address via an Ethereum smart contract (0xb614155Fd88114d40549b259457Bcf921Df091B9). This blockchain-based control method allows attackers to dynamically update infrastructure without releasing a new package version, complicating detection and blocking efforts.

A particularly dangerous feature is the dead-man’s switch: if an embedded GitHub token is revoked, the malware can wipe infected machines, complicating incident response. Organizations must isolate affected systems, preserve evidence, and rotate credentials before taking remediation steps.

Indicators of Compromise (IoCs)

  • Malicious npm package: [email protected]
  • C2 domain: iseekaigogo[.]com
  • Malicious files:
    • lib/setup.mjs (SHA-256: 25a0735d0db7dc40e5d45ce42d9c106067e6a66e184d967cfecfab17c3bcb5ef)
    • lib/Math_Symbol.js (SHA-256: b50a00900399ba99fb6ce1fc151519cb99d44320ef2a631f2237e1aea0ad6fec)
  • Ethereum contract: 0xb614155Fd88114d40549b259457Bcf921Df091B9
  • Compromised GitHub commit: 41b38f0

Any system that installed [email protected] should be considered fully compromised. Security teams are advised to remove the dependency, restore clean lockfiles, and rebuild environments while monitoring for unexpected Bun runtime executions.

Source: https://cybersecuritynews.com/tensorlake-npm-package/

Tensorlake TPRM report: https://www.rankiteo.com/company/tensorlake

"id": "ten1791476647",
"linkid": "tensorlake",
"type": "Cyber Attack",
"date": "10/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'AI/Serverless Platform',
                        'name': 'Tensorlake',
                        'size': '100,000+ lifetime installs',
                        'type': 'Software Package'}],
 'attack_vector': 'Malicious npm package (preinstall script)',
 'data_breach': {'data_exfiltration': True,
                 'personally_identifiable_information': True,
                 'sensitivity_of_data': 'High (PII, financial, and '
                                        'infrastructure credentials)',
                 'type_of_data_compromised': ['Environment variables',
                                              'Credential files',
                                              'Cryptocurrency wallet data']},
 'date_detected': '2026-10-08',
 'date_publicly_disclosed': '2026-10-08',
 'description': 'A compromised version of the Tensorlake npm package '
                '(v0.5.144) was published, containing a Shai-Hulud worm '
                'variant designed to steal developer secrets and propagate '
                'through software supply chains. The malware activates during '
                'installation, targeting environment variables, local '
                'credential files, and cryptocurrency wallets. The attack '
                'originated from a malicious GitHub commit and used '
                'blockchain-based command-and-control tactics for evasion.',
 'impact': {'brand_reputation_impact': 'Potential reputational damage to '
                                       'Tensorlake',
            'data_compromised': ['Environment variables (AWS, Kubernetes, '
                                 'Azure, Docker, GitHub Copilot)',
                                 'Local credential files (SSH, Vault tokens, '
                                 'CI/CD systems)',
                                 'Browser profiles (MetaMask, Phantom, '
                                 'Coinbase Wallet, Trust Wallet, and 10+ other '
                                 'crypto wallets)'],
            'identity_theft_risk': 'High (stolen credentials and PII)',
            'operational_impact': 'Potential lateral movement across software '
                                  'supply chains',
            'payment_information_risk': 'High (cryptocurrency wallet theft)',
            'systems_affected': ['Development environments',
                                 'CI/CD pipelines',
                                 'Cloud systems']},
 'initial_access_broker': {'entry_point': 'Compromised GitHub commit '
                                          '(41b38f0)'},
 'investigation_status': 'Ongoing',
 'motivation': ['Credential theft',
                'Cryptocurrency theft',
                'Supply chain compromise'],
 'post_incident_analysis': {'corrective_actions': ['Enhanced credential '
                                                   'security',
                                                   'Repository integrity '
                                                   'checks',
                                                   'Blockchain-based C2 '
                                                   'monitoring'],
                            'root_causes': ['Compromised package publishing '
                                            'credentials',
                                            'Malicious GitHub commit']},
 'ransomware': {'data_exfiltration': True},
 'recommendations': ['Remove [email protected] dependency immediately',
                     'Restore clean lockfiles and rebuild environments',
                     'Rotate all compromised credentials',
                     'Monitor for unexpected Bun runtime executions',
                     'Block the C2 domain (iseekaigogo[.]com) and Ethereum '
                     'contract (0xb614155Fd88114d40549b259457Bcf921Df091B9)'],
 'references': [{'date_accessed': '2026-10-08', 'source': 'Aikido Security'}],
 'response': {'containment_measures': ['Isolate affected systems',
                                       'Preserve evidence',
                                       'Rotate credentials'],
              'enhanced_monitoring': ['Monitor for unexpected Bun runtime '
                                      'executions'],
              'remediation_measures': ['Remove [email protected] dependency',
                                       'Restore clean lockfiles',
                                       'Rebuild environments'],
              'third_party_assistance': 'Aikido Security'},
 'title': 'Malicious Tensorlake npm Package Distributes Shai-Hulud Worm in '
          'Supply Chain Attack',
 'type': 'Supply Chain Attack',
 'vulnerability_exploited': 'Compromised package publishing credentials, '
                            'malicious GitHub commit'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.