threat_intelligence710 wordsRead on Huntaegis

Tensorlake npm package compromised by Shai-Hulud in latest software supply chain attack

1. Executive summary On October 8, 2026, the npm package tensorlake published version 0.5.144 carrying a malicious payload from the Shai-Hulud worm family. The package is the official TypeScript SDK for Tensorlake and is widely used, so this is a real supply chain risk for anyone who installed that specific version. The malicious release shipped through the project's normal GitHub Actions pipeline and even carried valid build provenance. Provenance confirms where a build came from, not that the source was clean. In this case the attacker modified the project's main branch first, then let the trusted pipeline publish the result. The most likely root cause is a compromised maintainer account, which is the signature behavior of Shai-Hulud. The bad version has since been removed from npm, and the previous version 0.5.143 is clean. If you installed 0.5.144, treat any credential on that machine as exposed and rotate it. 2. Affected packages - tensorlake@0.5.144 (npm). Published 2026-10-08 01:12:07 UTC. Now removed from the registry. - The six tensorlake-native-*@0.5.144 platform binary packages were published from the same run. They contain only the native binary and no install script, and we found no payload in them, but they should still be treated as part of the affected release and avoided. Not affected: tensorlake@0.5.143 and earlier. These do not contain the preinstall hook or the payload files. 3. Technical analysis What it does. The attacker added a preinstall hook to the package manifest that runs node lib/setup.mjs. Because npm runs preinstall before anything else, the code executes automatically on npm install, before any of your own application code. Two files were added to carry the payload: a small obfuscated loader (lib/setup.mjs) and a large obfuscated payload (lib/Math_Symbol.js, about 856 KB). The payload is tagged internally with a marker string, globalThis.WORMTAG='tensrlake', which is how the worm labels each package it infects. How it spreads and steals. This family works by stealing a developer's npm and GitHub credentials, then using those credentials to republish itself into other packages the victim controls and to create repositories that hold the stolen data. The loader checks whether it is running in CI (it inspects variables like CI, GITHUB_ACTIONS, GITLAB_CI, and RUNNER_ENVIRONMENT) and then pulls down and runs a second stage. The payload reaches out to the GitHub API and the npm registry to harvest tokens, propagate, and exfiltrate. What it targets. The payload hunts for a broad set of secrets, including npm tokens (.npmrc), SSH keys, cloud credentials for AWS, GCP, and Azure, Kubernetes and Docker configuration, HashiCorp Vault tokens, CI and registry tokens, GitHub CLI config, and environment files such as .env. On cloud hosts it also probes internal metadata endpoints to lift short lived cloud credentials. 4. Remediation - Block and avoid tensorlake@0.5.144. Pin to 0.5.143 until a known good release is published. - Remove any lockfile entries and package caches that reference 0.5.144, then reinstall from clean sources. - If 0.5.144 was installed anywhere, especially in CI, assume credential theft. Rotate npm tokens, GitHub tokens and SSH keys, cloud keys, and any secrets that were present on that host. - Review recent GitHub and npm activity for unexpected repository creation, new tokens, or unexpected publishes under affected accounts. - Consider installing with scripts disabled by default (for example npm install --ignore-scripts) in environments where that is practical, since the payload relies on a preinstall hook. 5. Indicators of compromise SHA256 - lib/setup.mjs: 25a0735d0db7dc40e5d45ce42d9c106067e6a66e184d967cfecfab17c3bcb5ef - lib/Math_Symbol.js: b50a00900399ba99fb6ce1fc151519cb99d44320ef2a631f2237e1aea0ad6fec Command and control - 0xb614155Fd88114d40549b259457Bcf921Df091B9 - ETH resolver wallet (EtherHiding). On-chain dead-drop the malware reads to fetch the current C2 domain. Durable indicator. - iseekaigogo[.]com - C2 domain. Daemon POSTs victim host/user/os. Disposable, rotated on-chain. URLs and services abused - https://api.github.com/ (used for credential checks, repository creation, and spread) - https://registry.npmjs.org/ (used for token checks, OIDC token exchange, maintainer lookup, and republishing) - Source repository: https://github.com/tensorlakeai/tensorlake, first malicious commit e90c47bbb2 (2026-10-07 01:20 UTC) - Release run that published the package: https://github.com/tensorlakeai/tensorlake/actions/runs/37706134202 IPs and internal endpoints probed (legitimate infrastructure targeted for credential theft, not attacker servers) - 169.254.169.254 (cloud instance metadata, for example AWS IMDS) - 169.254.170.2 (container and ECS task credentials) - 127.0.0.1:8200 (local HashiCorp Vault) What's next? When you're ready to take the next step in securing your software supply chain, here are 3 ways Endor Labs can help:

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.