Threat reportSupply ChainTL-2026-3085

Tensorlake npm Package Compromised (0.5.144) to Spread Shai-Hulud Worm Variant and Steal Developer Secrets

criticalACTIVE

Tensorlake npm Package Compromised (0.5.144) to Spread (TL-2026-3085), also tracked as Shai-Hulud variant, is a critical-severity supply-chain compromise, first published 2026-10-09 and last reviewed 2026-10-10. It has no confirmed attribution, affects Tensorlake tensorlake (npm package), maps to 27 MITRE ATT&CK techniques (T1003.007, T1005, T1027), and is covered by 9 detection rules and 47 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
0None referenced
Techniques
27MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
47Indicators of compromise

Key facts for TL-2026-3085

Threat ID
TL-2026-3085
Also known as
Shai-Hulud variant, Mini Shai-Hulud, Shai-Hulud: Here We Go Again
Severity
CRITICAL
Status
ACTIVE
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
technology, software-development, artificial-intelligence, cryptocurrency, cloud-services
Target regions
Global
Detection rules
9
Indicators of compromise
47
Updates
2026-10-10 · 3 updates · revalidated 3× · latest source

Malware and tooling in Tensorlake npm Package Compromised (0.5.144) to Spread

Malware and tooling: HackBrowserData, Shai-Hulud, phantom, HackBrowserData

How Tensorlake npm Package Compromised (0.5.144) to Spread works

The tensorlake npm package (100,000+ lifetime installs) was backdoored after the maintainer's GitHub identity was compromised; malicious version 0.5.144 runs a preinstall loader that fetches the Bun runtime and executes an obfuscated credential-stealing worm payload, a new build of the Shai-Hulud / Mini Shai-Hulud family. The payload steals cloud, CI/CD, SSH, browser, AI-tool and crypto-wallet secrets, propagates via stolen npm and GitHub tokens, and installs a dead-man's switch that deletes the victim's home directory if the stolen GitHub token is revoked.

On 2026-10-07 an attacker with control of a verified maintainer identity pushed a series of commits directly to the tensorlake GitHub repository through the GitHub web interface (first malicious commit ~01:20 UTC, additional payload-modifying commits through the morning, reported as 8 commits by SafeDep and StepSecurity). The commits added lib/setup.mjs (32,645 bytes) and lib/Math_Symbol.js (856,501 bytes) and a preinstall hook in package.json. The release workflow published tensorlake@0.5.144 to npm on 2026-10-08 (about 20 hours after the repository was first modified). SafeDep's automated detection flagged the release within minutes. npm removed the version, maintainers reverted the source (PR #1016) and released 0.5.145. Aikido reported that the package's PyPI and Cargo distributions showed no sign of compromise.

Execution chain: the preinstall script runs `node lib/setup.mjs`, a heavily obfuscated loader (RC4 plus custom string cipher) that skips CI runners, downloads Bun (1.3.13 per SafeDep) and uses it to execute the obfuscated lib/Math_Symbol.js. Using Bun instead of Node.js helps evade Node-focused security tooling. The payload sets a global WORMTAG build marker (value 'tensrlake'), uses AES-256-GCM to protect embedded files and shares a cipher salt (svksjrhjkcejg) with the earlier keyv/cacheable Mini Shai-Hulud wave. Aikido assessed the operator as more focused on quickly monetising developer endpoints than on proliferation, citing enhanced crypto-wallet targeting.

Collection: the worm gathers 46 environment variables (AWS, CI/CD identifiers, Vault tokens, cloud provider config) and 80+ credential file paths (SSH keys, .npmrc, .env, Docker and Kubernetes configs, cloud CLI configs, shell history, ~/.claude.json, ~/.kiro/settings/mcp.json, wallet files such as wallet.dat, Exodus, Electrum, Ledger Live, .ethereum/keystore, .monero). It targets 14 browser wallet extensions (MetaMask, Phantom, Coinbase Wallet, Rabby, Trust Wallet, TronLink, Ronin, Solflare, Keplr, Exodus, OKX, Rainbow, UniSat, SafePal) and pulls a HackBrowserData-style binary from C2 for browser passwords. It also queries AWS STS/SSM/Secrets Manager, reads GitHub Actions secrets from Runner.Worker process memory and harvests Kubernetes/Vault service tokens.

Command and control: primary C2 is HTTPS POST to iseekaigogo.com:443/router (with a /hbd/ endpoint). On failure the malware falls back to (1) reading an actor-controlled Ethereum smart contract (0xb614155Fd88114d40549b259457Bcf921Df091B9, selector 0x53ed5143, last updated 2026-09-21) through public RPC endpoints (35 queried, including eth.llamarpc.com, rpc.ankr.com, ethereum.publicnode.com), (2) searching GitHub for signed commits from the account thebeautifulmarchoftime, and (3) public dead-drop repositories with the description 'Shai-Hulud: Here We Go Again'. C2 responses are JSON whose `code` field is passed to eval(), giving remote code execution; beaconing recurs every 45-90 seconds after the initial exfiltration.

Propagation and persistence: with a stolen npm token the worm injects the payload and a preinstall hook into the victim's publishable packages, bumps the patch version and republishes (SafeDep notes spread requires ./dist/Math_Symbol.js on disk and a loader/filename mismatch, ai_init.js vs math_init.js, limiting reliability). With a stolen GitHub token it commits .claude/settings.json and .vscode/tasks.json persistence hooks as the fake author claude@users.noreply.github.com, adds a 'Run Copilot' workflow on branch dependabot/github_actions/format/setup-formatter that exfiltrates repository secrets and then deletes the run and branch.

Destructive dead-man's switch: a `gh-token-monitor` service (systemd user service with ~/.local/bin/gh-token-monitor.sh, macOS LaunchAgent under ~/.config/gh-token-monitor/, Windows scheduled task running %LOCALAPPDATA%\gh-token-monitor\monitor.ps1) checks the embedded GitHub token against the GitHub API every 60 seconds for up to 24 hours. If GitHub rejects the token it runs `rm -rf ~/` (Linux/macOS) or `Remove-Item -LiteralPath $env:USERPROFILE -Recurse -Force` (Windows). Responders must remove the monitor before revoking credentials.

No CVE or CVSS applies; this is a software supply-chain compromise. Actor attribution is unknown. Note on source discrepancy: SafeDep's page lists some timestamps as 2026-10-07 for the npm publish, while Aikido, StepSecurity and the news article place the publish on 2026-10-08; this record uses 2026-10-08.

MITRE ATT&CK techniques used in TL-2026-3085

Credential Access

T1003.007 OS Credential Dumping; T1528 Steal Application Access Token; T1552.001 Credentials In Files; T1552.004 Unsecured Credentials; T1552.005 Unsecured Credentials; T1555.003 Credentials from Web Browsers

Collection

T1005 Data from Local System; T1119 Automated Collection

Defense Evasion

T1027 Obfuscated Files or Information; T1480 Execution Guardrails

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service; T1567.001 Exfiltration Over Web Service

Persistence

T1053.005 Scheduled Task; T1543.001 Launch Agent; T1543.002 Systemd Service; T1546 Event Triggered Execution

Execution

T1059.001 PowerShell; T1059.004 Unix Shell; T1059.007 JavaScript

Command and Control

T1071.001 Web Protocols; T1102.001 Web Service; T1105 Ingress Tool Transfer; T1568 Dynamic Resolution

Initial Access

T1078 Valid Accounts; T1195.002 Compromise Software Supply Chain

Impact

T1485 Data Destruction

Affected products and versions in Tensorlake npm Package Compromised (0.5.144) to Spread

  • Tensorlake — tensorlake (npm package)
    Vulnerable versions: 0.5.144
    Fixed in: 0.5.145; 0.5.143 (last known-good)

Remediation for Tensorlake npm Package Compromised (0.5.144) to Spread

Patches

  • Maintainers reverted the malicious source (PR #1016) and released tensorlake 0.5.145; 0.5.143 is the last known-good pin

Immediate actions

  • Check for tensorlake@0.5.144 with `npm ls tensorlake` and lockfile inspection; pin to tensorlake@0.5.143 or upgrade to 0.5.145
  • BEFORE revoking any GitHub token, remove the token monitor: Linux `systemctl --user disable --now gh-token-monitor.service`; macOS `launchctl bootout` the gh-token-monitor LaunchAgent; Windows remove the gh-token-monitor scheduled task
  • Block iseekaigogo.com at DNS/proxy and alert on HTTPS POSTs to /router and /hbd/
  • Hunt for GitHub repositories with description 'Shai-Hulud: Here We Go Again' and commits authored by claude@users.noreply.github.com

Workarounds

  • Run npm install with --ignore-scripts for unverified packages
  • Restrict egress from build hosts to approved registries and block public Ethereum RPC endpoints where not needed

Longer-term hardening

  • Rotate all exposed credentials (GitHub, npm, cloud, SSH, Vault, Kubernetes, AI-tool API keys) after the monitor is removed
  • Audit .claude/settings.json, .vscode/tasks.json and GitHub workflows for unauthorized additions, including the dependabot/github_actions/format/setup-formatter branch and 'Run Copilot' workflow
  • Disable npm lifecycle scripts (ignore-scripts) in CI and developer environments and use package age/cooldown policies
  • Move crypto wallet funds if wallet extensions or keystores were present on an affected host; rebuild hosts when remediation completeness is uncertain

Weaknesses (CWE) in Tensorlake npm Package Compromised (0.5.144) to Spread

CWE-506, CWE-829, CWE-522

Timeline of Tensorlake npm Package Compromised (0.5.144) to Spread

  • Earlier ChainDrop/Shai-Hulud variant compromised npm packages including keyv and flat-cache (August 2026; exact day not stated in sources, per The Register).
  • Actor-controlled Ethereum contract 0xb614155Fd88114d40549b259457Bcf921Df091B9 (wallet 0x779f83aE56309682beDb04816c19d358c4B21040) last updated with C2 address, per Aikido, before the tensorlake compromise.
  • Eighth and final malicious commit pushed to tensorlake main at 03:57:54 UTC (SafeDep).
  • First malicious commit pushed to the tensorlake main branch around 01:20 UTC via the GitHub web interface under a verified maintainer identity; further commits through the morning added lib/setup.mjs, lib/Math_Symbol.js and the preinstall hook (payload commit 41b38f09; StepSecurity reports seven additional payload-modifying commits until about 07:00 UTC).
  • OX Security observed 5 public GitHub repositories (description 'Shai-Hulud: Here We Go Again') holding stolen credentials following the attack; the 0.5.144 release run 37706134202 also published six tensorlake-native-*@0.5.144 packages.
  • Socket flagged the malicious release about 11 minutes after publication (SafeDep reports about 8 minutes).
  • Cyber Security News published coverage of the compromise, noting 100,000+ lifetime installs and the token-revocation wipe behavior.
  • npm removed the malicious version; maintainers reverted the source in PR #1016 and released tensorlake 0.5.145 (per SafeDep).
  • Aikido, StepSecurity and SafeDep published technical analyses identifying the Shai-Hulud variant, the iseekaigogo.com C2, the Ethereum contract fallback and the gh-token-monitor dead-man's switch.
  • Release workflow published tensorlake@0.5.144 to npm roughly 20 hours after the first malicious commit (StepSecurity: 01:12 UTC); SafeDep's automated detection flagged it within minutes.

Update history for TL-2026-3085

Sources cited for Tensorlake npm Package Compromised (0.5.144) to Spread

Detection coverage for TL-2026-3085

As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3085 across Splunk SPL, Microsoft KQL and Sigma, covering 47 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
47 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats