Tensorlake npm Compromise: Shai-Hulud Worm Shows Machine Identities Need Zero Trust

A malicious Tensorlake SDK release carried the Shai-Hulud credential-stealing worm into AI agent infrastructure, caught within 11 minutes but still exposing tokens, keys and secrets on any machine that installed it.

Updated 8 October 2026. This briefing separates what has been confirmed from what has only been claimed, and will be updated as the facts develop.

On 7 October 2026 at 01:20 UTC, a rogue commit was pushed to the main branch of the GitHub repository tensorlakeai/tensorlake under a maintainer's name. A day later, the repository's release workflow published version 0.5.144 of the "tensorlake" npm package, a TypeScript SDK used to build and manage Tensorlake's AI agent sandboxes and cloud services. The package has around 12,000 downloads a week and the GitHub repository has over a thousand stars.

Security firm Socket's engine flagged the malicious version 11 minutes after publication. Npm removed it from the registry and Tensorlake pulled the package, replacing it with a clean 0.5.145. According to Socket and The Hacker News, the release carried a preinstall hook that launched an obfuscated loader running on the Bun runtime, identified as a variant of the Shai-Hulud worm (also tracked as ChainDrop), the same family behind the August 2026 compromise of npm packages including keyv and flat-cache.

Analysis by Socket and StepSecurity shows the malware harvests credentials from local files, CI environments, Kubernetes and Vault, drops the HackBrowserData binary, exfiltrates data to an Ethereum-contract-resolved command-and-control endpoint with GitHub as a fallback, and attempts to self-propagate by republishing itself through compromised publishing identities. It also plants a PowerShell "hostage token" monitor: if a victim revokes a stolen GitHub token, the malware can trigger a destructive routine, including deletion of the user's home directory in some conditions.

What is confirmed, and what is not

  • Confirmed: version 0.5.144 of the tensorlake npm package was compromised and contained credential-stealing, persistence and self-propagation code, per Socket, The Hacker News and The Register.
  • Confirmed: the malicious version was live for roughly 11 minutes before detection, and both npm and Tensorlake removed it.
  • Confirmed: the malware is designed to steal npm tokens, GitHub tokens, AWS credentials, Vault and Kubernetes credentials, SSH keys, .env files, cryptocurrency wallets, messaging app data, and configuration files tied to tools including Claude, Cursor, Kiro, Windsurf and Zed.
  • Not known: the full scope of impact. The Register states plainly that "impact remains unknown" and no figures for actual compromised downstream systems have been published in these sources.
  • Not known: how the attacker obtained the access needed to push the rogue commit under a maintainer's name. The sources describe the mechanism of the malware but not the initial access vector into the Tensorlake repository.

The identity angle

This incident is fundamentally about machine and developer identities, not end users. The malware targets exactly the credentials that let software act on an organisation's behalf: npm publishing tokens, GitHub tokens, cloud service credentials, CI/CD secrets, Vault and Kubernetes tokens, and SSH keys. Socket noted that teams may isolate an AI agent's generated code inside a sandbox while installing its SDK on a workstation or build runner that holds deployment credentials and other secrets; code run during installation inherits the permissions of the installing process. In other words, the sandbox protects against untrusted AI-authored code, but it does nothing to protect the developer machine or build server where the SDK itself is installed. A single maintainer identity, compromised enough to push to main and trigger a release workflow, was sufficient to distribute the worm to every downstream installer. The worm's design, which enumerates packages tied to the victim's publishing identity and republishes itself, shows it specifically targets identity as the propagation mechanism, not just a payload to collect.

The pattern is not new

The sources note that ChainDrop, the technique family behind this compromise, was first documented in early August 2026 when it compromised hundreds of npm packages, including Keyv and Cacheable, using the same obfuscated Bun-based payload approach. Shai-Hulud's destructive token-monitor tactic was also observed in earlier waves of the worm.

What to check this week

  1. Inventory which build servers, CI runners and developer workstations have the tensorlake npm package installed, and check specifically for version 0.5.144.
  2. If found, do not simply uninstall: rebuild the affected machine from a trusted image before restoring access to any secrets, as Socket recommends.
  3. Disable any token-monitoring or persistence mechanisms before revoking affected GitHub tokens, since the malware can trigger destructive action on revocation.
  4. Rotate all credentials that may have been accessible to the installing process, including npm tokens, GitHub tokens, AWS keys, Vault tokens, Kubernetes credentials and SSH keys, not just those tied to the Tensorlake SDK directly.
  5. Review CI/CD pipeline permissions so that package installation steps do not run with the same privilege level as deployment and secrets access.
  6. Check for unexpected .claude/settings.json or .vscode/tasks.json files written into repositories, as these can cause the malware to re-execute when a project is opened in affected editors.
  7. Apply package-pinning and provenance verification (such as Sigstore checks) for critical SDK dependencies, particularly those used in AI agent and sandbox tooling.

The takeaway

The malware was caught fast, but the exposure window is not the main story. What matters is that a single compromised maintainer identity and a standard install process were enough to put every credential on a build machine at risk, sandbox or no sandbox. Machine identities and developer workstation permissions deserve the same scrutiny as human user accounts.

If you would like a second pair of eyes on your exposure, get in touch.

Sources and further reading

  1. Shai-Hulud worm makes jump to AI infrastructure with Tensorlake compromise (The Register)
  2. Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm (The Hacker News)

Source links support the documented product behaviour. Recommendations and labelled examples are editorial guidance.