Threat reportSupply ChainTL-2026-3085
Tensorlake npm Package Compromised (0.5.144) to Spread Shai-Hulud Worm Variant and Steal Developer Secrets
Tensorlake npm Package Compromised (0.5.144) to Spread (TL-2026-3085), also tracked as Shai-Hulud variant, is a critical-severity supply-chain compromise, first published 2026-10-09 and last reviewed 2026-10-10. It has no confirmed attribution, affects Tensorlake tensorlake (npm package), maps to 27 MITRE ATT&CK techniques (T1003.007, T1005, T1027), and is covered by 9 detection rules and 47 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 0None referenced
- Techniques
- 27MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 47Indicators of compromise
Key facts for TL-2026-3085
- Threat ID
- TL-2026-3085
- Also known as
- Shai-Hulud variant, Mini Shai-Hulud, Shai-Hulud: Here We Go Again
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- technology, software-development, artificial-intelligence, cryptocurrency, cloud-services
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 47
- Updates
- 2026-10-10 · 3 updates · revalidated 3× · latest source
Malware and tooling in Tensorlake npm Package Compromised (0.5.144) to Spread
Malware and tooling: HackBrowserData, Shai-Hulud, phantom, HackBrowserData
How Tensorlake npm Package Compromised (0.5.144) to Spread works
The tensorlake npm package (100,000+ lifetime installs) was backdoored after the maintainer's GitHub identity was compromised; malicious version 0.5.144 runs a preinstall loader that fetches the Bun runtime and executes an obfuscated credential-stealing worm payload, a new build of the Shai-Hulud / Mini Shai-Hulud family. The payload steals cloud, CI/CD, SSH, browser, AI-tool and crypto-wallet secrets, propagates via stolen npm and GitHub tokens, and installs a dead-man's switch that deletes the victim's home directory if the stolen GitHub token is revoked.
On 2026-10-07 an attacker with control of a verified maintainer identity pushed a series of commits directly to the tensorlake GitHub repository through the GitHub web interface (first malicious commit ~01:20 UTC, additional payload-modifying commits through the morning, reported as 8 commits by SafeDep and StepSecurity). The commits added lib/setup.mjs (32,645 bytes) and lib/Math_Symbol.js (856,501 bytes) and a preinstall hook in package.json. The release workflow published tensorlake@0.5.144 to npm on 2026-10-08 (about 20 hours after the repository was first modified). SafeDep's automated detection flagged the release within minutes. npm removed the version, maintainers reverted the source (PR #1016) and released 0.5.145. Aikido reported that the package's PyPI and Cargo distributions showed no sign of compromise.
Execution chain: the preinstall script runs `node lib/setup.mjs`, a heavily obfuscated loader (RC4 plus custom string cipher) that skips CI runners, downloads Bun (1.3.13 per SafeDep) and uses it to execute the obfuscated lib/Math_Symbol.js. Using Bun instead of Node.js helps evade Node-focused security tooling. The payload sets a global WORMTAG build marker (value 'tensrlake'), uses AES-256-GCM to protect embedded files and shares a cipher salt (svksjrhjkcejg) with the earlier keyv/cacheable Mini Shai-Hulud wave. Aikido assessed the operator as more focused on quickly monetising developer endpoints than on proliferation, citing enhanced crypto-wallet targeting.
Collection: the worm gathers 46 environment variables (AWS, CI/CD identifiers, Vault tokens, cloud provider config) and 80+ credential file paths (SSH keys, .npmrc, .env, Docker and Kubernetes configs, cloud CLI configs, shell history, ~/.claude.json, ~/.kiro/settings/mcp.json, wallet files such as wallet.dat, Exodus, Electrum, Ledger Live, .ethereum/keystore, .monero). It targets 14 browser wallet extensions (MetaMask, Phantom, Coinbase Wallet, Rabby, Trust Wallet, TronLink, Ronin, Solflare, Keplr, Exodus, OKX, Rainbow, UniSat, SafePal) and pulls a HackBrowserData-style binary from C2 for browser passwords. It also queries AWS STS/SSM/Secrets Manager, reads GitHub Actions secrets from Runner.Worker process memory and harvests Kubernetes/Vault service tokens.
Command and control: primary C2 is HTTPS POST to iseekaigogo.com:443/router (with a /hbd/ endpoint). On failure the malware falls back to (1) reading an actor-controlled Ethereum smart contract (0xb614155Fd88114d40549b259457Bcf921Df091B9, selector 0x53ed5143, last updated 2026-09-21) through public RPC endpoints (35 queried, including eth.llamarpc.com, rpc.ankr.com, ethereum.publicnode.com), (2) searching GitHub for signed commits from the account thebeautifulmarchoftime, and (3) public dead-drop repositories with the description 'Shai-Hulud: Here We Go Again'. C2 responses are JSON whose `code` field is passed to eval(), giving remote code execution; beaconing recurs every 45-90 seconds after the initial exfiltration.
Propagation and persistence: with a stolen npm token the worm injects the payload and a preinstall hook into the victim's publishable packages, bumps the patch version and republishes (SafeDep notes spread requires ./dist/Math_Symbol.js on disk and a loader/filename mismatch, ai_init.js vs math_init.js, limiting reliability). With a stolen GitHub token it commits .claude/settings.json and .vscode/tasks.json persistence hooks as the fake author claude@users.noreply.github.com, adds a 'Run Copilot' workflow on branch dependabot/github_actions/format/setup-formatter that exfiltrates repository secrets and then deletes the run and branch.
Destructive dead-man's switch: a `gh-token-monitor` service (systemd user service with ~/.local/bin/gh-token-monitor.sh, macOS LaunchAgent under ~/.config/gh-token-monitor/, Windows scheduled task running %LOCALAPPDATA%\gh-token-monitor\monitor.ps1) checks the embedded GitHub token against the GitHub API every 60 seconds for up to 24 hours. If GitHub rejects the token it runs `rm -rf ~/` (Linux/macOS) or `Remove-Item -LiteralPath $env:USERPROFILE -Recurse -Force` (Windows). Responders must remove the monitor before revoking credentials.
No CVE or CVSS applies; this is a software supply-chain compromise. Actor attribution is unknown. Note on source discrepancy: SafeDep's page lists some timestamps as 2026-10-07 for the npm publish, while Aikido, StepSecurity and the news article place the publish on 2026-10-08; this record uses 2026-10-08.
MITRE ATT&CK techniques used in TL-2026-3085
Credential Access
T1003.007 OS Credential Dumping; T1528 Steal Application Access Token; T1552.001 Credentials In Files; T1552.004 Unsecured Credentials; T1552.005 Unsecured Credentials; T1555.003 Credentials from Web Browsers
Collection
T1005 Data from Local System; T1119 Automated Collection
Defense Evasion
T1027 Obfuscated Files or Information; T1480 Execution Guardrails
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service; T1567.001 Exfiltration Over Web Service
Persistence
T1053.005 Scheduled Task; T1543.001 Launch Agent; T1543.002 Systemd Service; T1546 Event Triggered Execution
Execution
T1059.001 PowerShell; T1059.004 Unix Shell; T1059.007 JavaScript
Command and Control
T1071.001 Web Protocols; T1102.001 Web Service; T1105 Ingress Tool Transfer; T1568 Dynamic Resolution
Initial Access
T1078 Valid Accounts; T1195.002 Compromise Software Supply Chain
Impact
Affected products and versions in Tensorlake npm Package Compromised (0.5.144) to Spread
- Tensorlake — tensorlake (npm package)
Vulnerable versions: 0.5.144
Fixed in: 0.5.145; 0.5.143 (last known-good)
Remediation for Tensorlake npm Package Compromised (0.5.144) to Spread
Patches
- Maintainers reverted the malicious source (PR #1016) and released tensorlake 0.5.145; 0.5.143 is the last known-good pin
Immediate actions
- Check for tensorlake@0.5.144 with `npm ls tensorlake` and lockfile inspection; pin to tensorlake@0.5.143 or upgrade to 0.5.145
- BEFORE revoking any GitHub token, remove the token monitor: Linux `systemctl --user disable --now gh-token-monitor.service`; macOS `launchctl bootout` the gh-token-monitor LaunchAgent; Windows remove the gh-token-monitor scheduled task
- Block iseekaigogo.com at DNS/proxy and alert on HTTPS POSTs to /router and /hbd/
- Hunt for GitHub repositories with description 'Shai-Hulud: Here We Go Again' and commits authored by claude@users.noreply.github.com
Workarounds
- Run npm install with --ignore-scripts for unverified packages
- Restrict egress from build hosts to approved registries and block public Ethereum RPC endpoints where not needed
Longer-term hardening
- Rotate all exposed credentials (GitHub, npm, cloud, SSH, Vault, Kubernetes, AI-tool API keys) after the monitor is removed
- Audit .claude/settings.json, .vscode/tasks.json and GitHub workflows for unauthorized additions, including the dependabot/github_actions/format/setup-formatter branch and 'Run Copilot' workflow
- Disable npm lifecycle scripts (ignore-scripts) in CI and developer environments and use package age/cooldown policies
- Move crypto wallet funds if wallet extensions or keystores were present on an affected host; rebuild hosts when remediation completeness is uncertain
Weaknesses (CWE) in Tensorlake npm Package Compromised (0.5.144) to Spread
Timeline of Tensorlake npm Package Compromised (0.5.144) to Spread
- Earlier ChainDrop/Shai-Hulud variant compromised npm packages including keyv and flat-cache (August 2026; exact day not stated in sources, per The Register).
- Actor-controlled Ethereum contract 0xb614155Fd88114d40549b259457Bcf921Df091B9 (wallet 0x779f83aE56309682beDb04816c19d358c4B21040) last updated with C2 address, per Aikido, before the tensorlake compromise.
- Eighth and final malicious commit pushed to tensorlake main at 03:57:54 UTC (SafeDep).
- First malicious commit pushed to the tensorlake main branch around 01:20 UTC via the GitHub web interface under a verified maintainer identity; further commits through the morning added lib/setup.mjs, lib/Math_Symbol.js and the preinstall hook (payload commit 41b38f09; StepSecurity reports seven additional payload-modifying commits until about 07:00 UTC).
- OX Security observed 5 public GitHub repositories (description 'Shai-Hulud: Here We Go Again') holding stolen credentials following the attack; the 0.5.144 release run 37706134202 also published six tensorlake-native-*@0.5.144 packages.
- Socket flagged the malicious release about 11 minutes after publication (SafeDep reports about 8 minutes).
- Cyber Security News published coverage of the compromise, noting 100,000+ lifetime installs and the token-revocation wipe behavior.
- npm removed the malicious version; maintainers reverted the source in PR #1016 and released tensorlake 0.5.145 (per SafeDep).
- Aikido, StepSecurity and SafeDep published technical analyses identifying the Shai-Hulud variant, the iseekaigogo.com C2, the Ethereum contract fallback and the gh-token-monitor dead-man's switch.
- Release workflow published tensorlake@0.5.144 to npm roughly 20 hours after the first malicious commit (StepSecurity: 01:12 UTC); SafeDep's automated detection flagged it within minutes.
Update history for TL-2026-3085
- 2026-10-10 — Tensorlake npm package (tensorlake@0.5.144) compromised by Shai-Hulud self-propagating worm (ChainDrop): What changed No severity/exploitability/status change (already CRITICAL/ACTIVE). Affected scope broadened: six tensorlake-native- @0.5.144 platform packages published in the same release. New indicators (12) Native package set, opensearch_i
- 2026-10-09 — Tensorlake npm Package Hijacked (v0.5.144) to Spread Shai-Hulud Supply Chain Worm Variant: What changed No change to severity (CRITICAL), exploitability (ACTIVE), status or attribution; additive enrichment only. New indicators (3) 3 new indicators: first malicious commit hash e90c47bbb208e99cac8aa678405b2133f6cb3f52 (version-bump
- 2026-10-09 — Shai-Hulud (Mini Shai-Hulud / ChainDrop) worm compromises Tensorlake npm SDK v0.5.144, jumping to AI infrastructure: What changed No severity, exploitability or status change. The newer report rates the threat HIGH versus the existing CRITICAL; this is not treated as a downgrade and the existing value is retained. New indicators (11) 11 additional behavio
Sources cited for Tensorlake npm Package Compromised (0.5.144) to Spread
- Tensorlake npm Package Compromised to Spread Shai-Hulud Worm and Steal Developer Secrets
- tensorlake NPM package compromised with Shai Hulud worm (Aikido)
- Tensorlake npm Package Compromised: A Worm With a Hostage Token That Wipes Your Machine If You Revoke It (StepSecurity)
- tensorlake 0.5.144 npm Compromise Ships Mini Shai-Hulud (SafeDep)
- Tensorlake npm Package Compromised: Shai-Hulud Worm Hits AI Developers
- Tensorlake npm Compromise Spreads Credential-Stealing Worm With Destructive Token Monitor (Mallory)
- Researchers Spot Modified Shai-Hulud Worm (background on earlier Shai-Hulud waves)
Detection coverage for TL-2026-3085
As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3085 across Splunk SPL, Microsoft KQL and Sigma, covering 47 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.