# Tensorlake npm Package Compromised (0.5.144) to Spread Shai-Hulud Worm Variant and Steal Developer Secrets

> The tensorlake npm package (100,000+ lifetime installs) was backdoored after the maintainer's GitHub identity was compromised; malicious version 0.5.144 runs a preinstall loader that fetches the Bun runtime and executes an obfuscated credential-stealing worm payload, a new build of the Shai-Hulud / Mini Shai-Hulud family. The payload steals cloud, CI/CD, SSH, browser, AI-tool and crypto-wallet secrets, propagates via stolen npm and GitHub tokens, and installs a dead-man's switch that deletes the victim's home directory if the stolen GitHub token is revoked.

- **Published:** 2026-10-09T00:00:00Z
- **Last reviewed:** 2026-10-10T06:26:07.505Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3085
- **ID:** TL-2026-3085
- **Severity:** CRITICAL
- **Category:** SUPPLY_CHAIN
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 47 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On 2026-10-07 an attacker with control of a verified maintainer identity pushed a series of commits directly to the tensorlake GitHub repository through the GitHub web interface (first malicious commit ~01:20 UTC, additional payload-modifying commits through the morning, reported as 8 commits by SafeDep and StepSecurity). The commits added lib/setup.mjs (32,645 bytes) and lib/Math_Symbol.js (856,501 bytes) and a preinstall hook in package.json. The release workflow published tensorlake@0.5.144 to npm on 2026-10-08 (about 20 hours after the repository was first modified). SafeDep's automated detection flagged the release within minutes. npm removed the version, maintainers reverted the source (PR #1016) and released 0.5.145. Aikido reported that the package's PyPI and Cargo distributions showed no sign of compromise.

Execution chain: the preinstall script runs `node lib/setup.mjs`, a heavily obfuscated loader (RC4 plus custom string cipher) that skips CI runners, downloads Bun (1.3.13 per SafeDep) and uses it to execute the obfuscated lib/Math_Symbol.js. Using Bun instead of Node.js helps evade Node-focused security tooling. The payload sets a global WORMTAG build marker (value 'tensrlake'), uses AES-256-GCM to protect embedded files and shares a cipher salt (svksjrhjkcejg) with the earlier keyv/cacheable Mini Shai-Hulud wave. Aikido assessed the operator as more focused on quickly monetising developer endpoints than on proliferation, citing enhanced crypto-wallet targeting.

Collection: the worm gathers 46 environment variables (AWS, CI/CD identifiers, Vault tokens, cloud provider config) and 80+ credential file paths (SSH keys, .npmrc, .env, Docker and Kubernetes configs, cloud CLI configs, shell history, ~/.claude.json, ~/.kiro/settings/mcp.json, wallet files such as wallet.dat, Exodus, Electrum, Ledger Live, .ethereum/keystore, .monero). It targets 14 browser wallet extensions (MetaMask, Phantom, Coinbase Wallet, Rabby, Trust Wallet, TronLink, Ronin, Solflare, Keplr, Exodus, OKX, Rainbow, UniSat, SafePal) and pulls a HackBrowserData-style binary from C2 for browser passwords. It also queries AWS STS/SSM/Secrets Manager, reads GitHub Actions secrets from Runner.Worker process memory and harvests Kubernetes/Vault service tokens.

Command and control: primary C2 is HTTPS POST to iseekaigogo.com:443/router (with a /hbd/ endpoint). On failure the malware falls back to (1) reading an actor-controlled Ethereum smart contract (0xb614155Fd88114d40549b259457Bcf921Df091B9, selector 0x53ed5143, last updated 2026-09-21) through public RPC endpoints (35 queried, including eth.llamarpc.com, rpc.ankr.com, ethereum.publicnode.com), (2) searching GitHub for signed commits from the account thebeautifulmarchoftime, and (3) public dead-drop repositories with the description 'Shai-Hulud: Here We Go Again'. C2 responses are JSON whose `code` field is passed to eval(), giving remote code execution; beaconing recurs every 45-90 seconds after the initial exfiltration.

Propagation and persistence: with a stolen npm token the worm injects the payload and a preinstall hook into the victim's publishable packages, bumps the patch version and republishes (SafeDep notes spread requires ./dist/Math_Symbol.js on disk and a loader/filename mismatch, ai_init.js vs math_init.js, limiting reliability). With a stolen GitHub token it commits .claude/settings.json and .vscode/tasks.json persistence hooks as the fake author claude@users.noreply.github.com, adds a 'Run Copilot' workflow on branch dependabot/github_actions/format/setup-formatter that exfiltrates repository secrets and then deletes the run and branch.

Destructive dead-man's switch: a `gh-token-monitor` service (systemd user service with ~/.local/bin/gh-token-monitor.sh, macOS LaunchAgent under ~/.config/gh-token-monitor/, Windows scheduled task running %LOCALAPPDATA%\gh-token-monitor\monitor.ps1) checks the embedded GitHub token against the GitHub API every 60 seconds for up to 24 hours. If GitHub rejects the token it runs `rm -rf ~/` (Linux/macOS) or `Remove-Item -LiteralPath $env:USERPROFILE -Recurse -Force` (Windows). Responders must remove the monitor before revoking credentials.

No CVE or CVSS applies; this is a software supply-chain compromise. Actor attribution is unknown. Note on source discrepancy: SafeDep's page lists some timestamps as 2026-10-07 for the npm publish, while Aikido, StepSecurity and the news article place the publish on 2026-10-08; this record uses 2026-10-08.

## MITRE ATT&CK

- T1195.002 Compromise Software Supply Chain
- T1078 Valid Accounts
- T1059.007 JavaScript
- T1059.004 Unix Shell
- T1059.001 PowerShell
- T1543.002 Systemd Service
- T1543.001 Launch Agent
- T1053.005 Scheduled Task
- T1027 Obfuscated Files or Information
- T1480 Execution Guardrails
- T1552.001 Credentials In Files
- T1555.003 Credentials from Web Browsers
- T1528 Steal Application Access Token
- T1005 Data from Local System
- T1071.001 Web Protocols
- T1568 Dynamic Resolution
- T1567 Exfiltration Over Web Service
- T1485 Data Destruction
- T1552.004 Unsecured Credentials
- T1552.005 Unsecured Credentials
- T1003.007 OS Credential Dumping
- T1119 Automated Collection
- T1102.001 Web Service
- T1105 Ingress Tool Transfer
- T1041 Exfiltration Over C2 Channel
- T1567.001 Exfiltration Over Web Service
- T1546 Event Triggered Execution

## Sources

- [Tensorlake npm Package Compromised to Spread Shai-Hulud Worm and Steal Developer Secrets](https://cybersecuritynews.com/tensorlake-npm-package/)
- [tensorlake NPM package compromised with Shai Hulud worm (Aikido)](https://www.aikido.dev/blog/tensorlake-npm-package-compromised)
- [Tensorlake npm Package Compromised: A Worm With a Hostage Token That Wipes Your Machine If You Revoke It (StepSecurity)](https://www.stepsecurity.io/blog/tensorlake-npm-compromised-hostage-token-worm)
- [tensorlake 0.5.144 npm Compromise Ships Mini Shai-Hulud (SafeDep)](https://safedep.io/tensorlake-npm-compromise-mini-shai-hulud/)
- [Tensorlake npm Package Compromised: Shai-Hulud Worm Hits AI Developers](https://thecybersecguru.com/news/tensorlake-npm-package-compromised-shai-hulud-worm/)
- [Tensorlake npm Compromise Spreads Credential-Stealing Worm With Destructive Token Monitor (Mallory)](https://mallory.ai/stories/01a11981-edbb-79f1-8cdb-f2f56e94651e)
- [Researchers Spot Modified Shai-Hulud Worm (background on earlier Shai-Hulud waves)](https://thehackernews.com/2025/12/researchers-spot-modified-shai-hulud.html)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3085
