Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Compromised Tensorlake npm Package Delivers Credential-Stealing Malware

Compromised Tensorlake npm Package Delivers Credential-Stealing Malware

Posted on October 8, 2026 By CWS

The Tensorlake npm package, a TypeScript SDK designed for Tensorlake software and cloud services, has been compromised in a supply chain attack dubbed ChainDrop/Shai-Hulud. This breach has resulted in the dissemination of a credential-stealing worm, as reported by security firm Socket.

Malware Details and Impact

Version 0.5.144 of the Tensorlake package contained obfuscated malware that executed a variety of malicious activities, including credential theft and the execution of unauthorized code. This version has now been removed from the npm registry to prevent further downloads. The malware exploited a preinstall hook to deploy a JavaScript file that initiated the main worm, designed to extract sensitive information from various local and cloud environments.

The malware specifically targeted credentials stored in local files, CI environments, Kubernetes, and Vault systems. It included a binary for data exfiltration and was capable of maintaining persistent access to compromised systems even after the malicious package was removed.

Data Compromised by the Attack

The range of data stolen by this malware is extensive, including npm and GitHub tokens, AWS credentials, SSH keys, and sensitive files such as .env and cryptocurrency wallets. The attack also compromised messaging app data and configuration files linked to several AI and development tools.

To further propagate, the malware republished compromised package versions by utilizing the victim’s publishing identity and creating Sigstore provenance. It also manipulated GitHub Actions workflows, suggesting a deep infiltration into development processes.

Technical and Security Insights

The malware’s command-and-control operations were facilitated through an Ethereum contract, with GitHub serving as an alternative for staging stolen data. A component known as the “hostage token” employed PowerShell to monitor GitHub tokens, performing destructive actions if token revocation was detected.

According to StepSecurity, the breach originated from a rogue commit on October 7, 2026, under the guise of a trusted maintainer. The compromised version was subsequently published on the npm registry, emphasizing the sophisticated tactics used in this attack.

This incident is part of a broader pattern of supply chain attacks targeting AI infrastructure and tools, underscoring the growing threat to enterprise data security. Affected users are strongly advised to uninstall the compromised package and update their credentials to mitigate risks.

Conclusion and Recommendations

The compromise of the Tensorlake npm package highlights the ongoing vulnerabilities within supply chain systems, particularly those associated with artificial intelligence tools. Organizations are urged to remain vigilant, regularly review dependencies, and implement robust security measures to safeguard their data against such advanced threats.

The Hacker News Tags:AI security, cloud security, credential-stealing malware, Cybersecurity, GitHub, JavaScript, NPM, Shai-Hulud, supply chain attack, Tensorlake

Post navigation

Previous Post: Claude Haiku 5.5: Affordable AI Model for Enhanced Efficiency
Next Post: U.S. Offers Reward for Info on Chinese Hacker in COVID-19 Case

Related Posts

Critical cPanel Security Flaw Patched to Prevent Root Access Critical cPanel Security Flaw Patched to Prevent Root Access The Hacker News
Researchers Uncover BankBot-YNRK and DeliveryRAT Android Trojans Stealing Financial Data Researchers Uncover BankBot-YNRK and DeliveryRAT Android Trojans Stealing Financial Data The Hacker News
PowMix Botnet Targets Czech Workforce with Stealth Tactics PowMix Botnet Targets Czech Workforce with Stealth Tactics The Hacker News
Critical Vulnerability in Cursor Allows Windows Code Execution Critical Vulnerability in Cursor Allows Windows Code Execution The Hacker News
GPUGate Malware Uses Google Ads and Fake GitHub Commits to Target IT Firms GPUGate Malware Uses Google Ads and Fake GitHub Commits to Target IT Firms The Hacker News
Mitigating Risks of Exposed Endpoints in LLM Infrastructure Mitigating Risks of Exposed Endpoints in LLM Infrastructure The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • U.S. Offers Reward for Info on Chinese Hacker in COVID-19 Case
  • Compromised Tensorlake npm Package Delivers Credential-Stealing Malware
  • Claude Haiku 5.5: Affordable AI Model for Enhanced Efficiency
  • Elastic Addresses Critical Security Vulnerabilities
  • FBI Warns of Global FortiBleed Cyber Threat

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • U.S. Offers Reward for Info on Chinese Hacker in COVID-19 Case
  • Compromised Tensorlake npm Package Delivers Credential-Stealing Malware
  • Claude Haiku 5.5: Affordable AI Model for Enhanced Efficiency
  • Elastic Addresses Critical Security Vulnerabilities
  • FBI Warns of Global FortiBleed Cyber Threat

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark