Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

The Shai-Hulud Worm: A Sophisticated Credential-Stealing Malware in the Tensorlake npm Package




The Tensorlake npm package has been compromised as part of a ChainDrop / Shai-Hulud supply chain attack. The malicious version 0.5.144 of the package contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code. The affected package has been removed from the npm package registry, but the damage has already been done. Read the full story to learn more about this sophisticated credential-stealing malware and the measures you can take to protect your AI agent infrastructure.

  • Tensorlake npm package was compromised as part of a ChainDrop/Shai-Hulud supply chain attack.
  • Malicious version 0.5.144 of the package contained obfuscated malware that harvested credentials, exfiltrated secrets, and executed remotely supplied code.
  • Malware was designed to steal data from various sources, including npm tokens, GitHub tokens, AWS credentials, and SSH keys.
  • Malware used an Ethereum contract to resolve its command-and-control (C2) endpoint and GitHub as a fallback mechanism.
  • Malware contained a "hostage token" component that used a PowerShell monitor to poll GitHub for token validity.
  • Attack extended supply chain attacks to artificial intelligence (AI) agent infrastructure.
  • Users advised to remove malicious version and rotate credentials to mitigate damage.



  • The cybersecurity landscape has been plagued by numerous high-profile attacks in recent times, with the recent compromise of the Tensorlake npm package serving as a stark reminder of the ever-evolving nature of threats. The Tensorlake npm package, a TypeScript software development kit (SDK) for Tensorlake applications, sandboxes, and cloud services, was compromised as part of a ChainDrop / Shai-Hulud supply chain attack. The malicious version 0.5.144 of the package contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code. The affected package has been removed from the npm package registry, but the damage has already been done.

    The analysis of the compromised release reveals that it contains a preinstall hook designed to launch a JavaScript file ("package/lib/setup.mjs"), an obfuscated loader that launches the main credential-stealing and self-propagating worm ("package/lib/Math_Symbol.js") using the Bun runtime. The stealer malware is designed to harvest credentials across local files, CI environments, Kubernetes, and Vault sources. It also drops the HackBrowserData binary, exfiltrates the collected data, establishes persistence on the host, and facilitates the execution of remotely-supplied code.

    The types of data stolen by the malware are below - npm tokens, GitHub tokens, Amazon Web Services (AWS) credentials and secrets, HashiCorp Vault, Kubernetes credentials, SSH keys, .env files, cryptocurrency wallets, messaging app data, and configuration and MCP files associated with Anthropic Claude, Cursor, Kiro, Windsurf, and Zed. The malware also makes use of an Ethereum contract to resolve its command-and-control (C2) endpoint ("iseekaigogo[.]com"), with GitHub acting as a fallback mechanism to stage the encrypted stolen data in a public repository with the description "Shai-Hulud: Here We Go Again."

    The malware also contains a "hostage token" component that uses a PowerShell monitor to repeatedly poll "api.github.com/user" using the stolen GitHub token to check if the token is valid. Should the victim take steps to revoke the token, the monitor proceeds to execute an attacker-supplied handler through the "Invoke-Expression" cmdlet to execute PowerShell code designed to likely trigger a destructive routine - a tactic observed in earlier Shai-Hulud waves.

    According to StepSecurity, the malicious files were pushed to the main branch of tensorlakeai/tensorlake under a maintainer's name, after which the package was released from that same repository. The first rogue commit took place on October 7, 2026, at 01:20 a.m. UTC. A day later, the repository's release workflow published 0.5.144 to npm.

    The development extends the supply chain attack to artificial intelligence (AI) agent infrastructure, once again highlighting how threat actors are increasingly targeting AI tools and services to extract valuable data from enterprises. Users who have installed the malicious version are advised to remove it immediately and rotate their credentials.

    The recent compromise of the Tensorlake npm package serves as a stark reminder of the ever-evolving nature of threats. The use of obfuscated malware and the exploitation of supply chain attacks highlight the need for enterprises to implement robust security measures to protect their AI agent infrastructure. Furthermore, the use of Ethereum contracts and PowerShell monitors in the malware underscore the importance of keeping software up-to-date and implementing robust security protocols to prevent such attacks.

    The cybersecurity landscape is constantly evolving, and it is essential for enterprises to stay vigilant and implement robust security measures to protect their infrastructure from emerging threats. The recent compromise of the Tensorlake npm package serves as a stark reminder of the need for continued vigilance and proactive security measures.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/The-Shai-Hulud-Worm-A-Sophisticated-Credential-Stealing-Malware-in-the-Tensorlake-npm-Package-ehn.shtml

  • https://thehackernews.com/2026/10/tensorlake-npm-package-compromised-to.html

  • https://chiprook.com/s/20393-tensorlake-npm-package-compromised-to-spread-shai-hulud-credential

  • https://socket.dev/blog/tensorlake-compromise

  • https://www.microsoft.com/en-us/security/blog/2026/08/04/chaindrop-supply-chain-compromise-anatomy-self-propagating-worm/

  • https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/


  • Published: Thu Oct 8 02:41:26 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us