The Tensorlake npm package, a TypeScript SDK designed for Tensorlake software and cloud services, has been compromised in a supply chain attack dubbed ChainDrop/Shai-Hulud. This breach has resulted in the dissemination of a credential-stealing worm, as reported by security firm Socket.
Malware Details and Impact
Version 0.5.144 of the Tensorlake package contained obfuscated malware that executed a variety of malicious activities, including credential theft and the execution of unauthorized code. This version has now been removed from the npm registry to prevent further downloads. The malware exploited a preinstall hook to deploy a JavaScript file that initiated the main worm, designed to extract sensitive information from various local and cloud environments.
The malware specifically targeted credentials stored in local files, CI environments, Kubernetes, and Vault systems. It included a binary for data exfiltration and was capable of maintaining persistent access to compromised systems even after the malicious package was removed.
Data Compromised by the Attack
The range of data stolen by this malware is extensive, including npm and GitHub tokens, AWS credentials, SSH keys, and sensitive files such as .env and cryptocurrency wallets. The attack also compromised messaging app data and configuration files linked to several AI and development tools.
To further propagate, the malware republished compromised package versions by utilizing the victim’s publishing identity and creating Sigstore provenance. It also manipulated GitHub Actions workflows, suggesting a deep infiltration into development processes.
Technical and Security Insights
The malware’s command-and-control operations were facilitated through an Ethereum contract, with GitHub serving as an alternative for staging stolen data. A component known as the “hostage token” employed PowerShell to monitor GitHub tokens, performing destructive actions if token revocation was detected.
According to StepSecurity, the breach originated from a rogue commit on October 7, 2026, under the guise of a trusted maintainer. The compromised version was subsequently published on the npm registry, emphasizing the sophisticated tactics used in this attack.
This incident is part of a broader pattern of supply chain attacks targeting AI infrastructure and tools, underscoring the growing threat to enterprise data security. Affected users are strongly advised to uninstall the compromised package and update their credentials to mitigate risks.
Conclusion and Recommendations
The compromise of the Tensorlake npm package highlights the ongoing vulnerabilities within supply chain systems, particularly those associated with artificial intelligence tools. Organizations are urged to remain vigilant, regularly review dependencies, and implement robust security measures to safeguard their data against such advanced threats.
