Tensorlake npm SDK hijacked to spread Shai-Hulud worm with token-revocation wiper
Version 0.5.144 of the tensorlake npm package shipped a credential-stealing worm that can wipe a developer's home directory if the stolen GitHub token is revoked.
At a glance
- Malicious [email protected] was published to npm on October 8 at 01:12 UTC, according to Socket.
- The payload steals npm, GitHub, cloud, Kubernetes, Vault and SSH secrets and republishes the victim's own packages.
- A 'hostage token' monitor can delete the user's home directory if the stolen GitHub token is revoked first.
- Researchers advise removing the monitor before rotating credentials and reverting to 0.5.143.
Attackers compromised the official npm package of Tensorlake, a TypeScript SDK for AI agent infrastructure, and published a version laced with a self-propagating credential-stealing worm linked to the Shai-Hulud family, according to separate reports from Socket and StepSecurity published on October 8. The malicious release, [email protected], carries a so-called "hostage token" mechanism that can wipe a developer's home directory if the stolen GitHub token is revoked before the malware is removed, making the order of incident response unusually important.
What happened
StepSecurity said the first malicious commit landed directly on the main branch of the tensorlakeai/tensorlake GitHub repository on October 7 at 01:20 UTC under a maintainer's name, followed by seven more commits that never went through a pull request. The project's own release workflow then published version 0.5.144 to npm on October 8 at 01:12 UTC. Socket said it flagged the release about 11 minutes later. The package has roughly 12,000 weekly downloads, Socket noted, adding that this does not reflect downloads of the malicious version or confirmed infections. How the attackers obtained access has not been disclosed.
Because the release was built from the project's own repository, it carries a valid npm provenance attestation. "The attestation says where a package was built. It doesn't say the code is safe," StepSecurity wrote. The Hacker News linked the incident to the ChainDrop campaign first documented in August.
Technical details
A preinstall hook runs lib/setup.mjs, an obfuscated loader that launches a roughly 856 KB payload, lib/Math_Symbol.js, with the Bun runtime. According to Socket, the payload harvests npm and GitHub tokens, AWS credentials, local HashiCorp Vault data, Kubernetes service-account tokens, SSH keys, .env files, crypto wallets, messaging app data and configuration files of AI coding tools. StepSecurity reported that the loader skips execution on CI systems, making developer machines the main target, while Socket's report also lists CI-related credential sources.
The worm enumerates packages tied to the victim's npm identity and republishes infected versions. With a GitHub token, it commits .claude/settings.json and .vscode/tasks.json files to reachable repositories so the code runs again when a project is opened, using the fake author [email protected]. Command-and-control is resolved through an Ethereum contract, with iseekaigogo.com and public GitHub repositories described as "Shai-Hulud: Here We Go Again" used for exfiltration.
The gh-token-monitor service checks the stolen token against the GitHub API every 60 seconds for up to 24 hours, StepSecurity said. If the token is rejected, it runs rm -rf ~/ on Linux and macOS or deletes the user profile on Windows.
What to do
Researchers recommend checking lockfiles for 0.5.144, pinning [email protected], clearing node_modules and the npm cache, and setting ignore-scripts=true. Before revoking any token, back up data and remove the monitor: ~/.config/gh-token-monitor/, ~/.local/bin/gh-token-monitor.sh, the related systemd unit or com.user.gh-token-monitor.plist LaunchAgent, and on Windows the logon scheduled task running monitor.ps1. Only then rotate all exposed credentials and audit accounts for unexpected package releases or commits. Machines that cannot be confirmed clean should be rebuilt.
Sources
- TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack — Socket
- Tensorlake npm Package Compromised: A Worm With a Hostage Token That Wipes Your Machine If You Revoke It — StepSecurity
- Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm — The Hacker News
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



