Tensorlake npm Package Compromised to Spread Shai-Hulud Worm and Steal Developer Secrets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


A malicious release of the Tensorlake npm package has been published with a Shai-Hulud worm variant that can steal developer secrets and attempt to spread through connected software supply chains.

The affected version, [email protected], was released on October 8, 2026. Tensorlake is a serverless sandbox platform for AI agents, and its npm package has recorded more than 100,000 lifetime installs, increasing the potential reach of the incident.

Aikido’s technical report says the package’s PyPI and Cargo distributions showed no sign of compromise at the time of analysis. The incident shows once again how a trusted dependency can become a route into developer laptops, CI/CD systems, cloud environments, and package publishing accounts.

A poisoned npm package does not need a user to open a suspicious attachment or visit a malicious page. In this case, the malware is triggered during installation, allowing it to run before developers begin using the package.

The pattern closely follows the behavior seen in recent Shai-Hulud worm activity, where stolen package publishing credentials can turn one compromised development environment into a wider supply-chain problem.

Analysts from Aikido identified the malicious Tensorlake release and linked its payload to a new Shai-Hulud variant rather than a simple reinfection from an earlier wave.

The researchers said the code sets a unique global WORMTAG marker before launching its hidden logic, a detail that points to a fresh compromise of the Tensorlake package.

The malware was placed in the project’s GitHub repository after an actor made verified commits using a maintainer identity on October 7.

A malicious file upload in commit 41b38f0 added the payload, and the repository remained compromised for about 20 hours before the npm release was published.

Tensorlake npm Package Compromised

The infection begins with a preinstall script that calls node lib/setup.mjs. That script is heavily obscured and downloads the Bun JavaScript runtime before using it to launch lib/Math_Symbol.js, which contains the main Shai-Hulud payload.

The use of Bun is important because many security controls pay closer attention to Node.js activity than a newly downloaded runtime.

Similar evasion methods have appeared in Bun-based npm malware campaigns, where attackers use a legitimate developer runtime to hide execution from script-focused checks.

Once active, the malware tries to collect secrets from environment variables, local credential files, cloud settings, CI/CD systems, Docker, Kubernetes, SSH folders, Vault tokens, GitHub-related data, and browser profiles.

It searches for AWS access keys, Kubernetes configurations, Azure data, Docker credentials, and GitHub Copilot settings.

It also looks for browser extension databases linked to cryptocurrency wallets, including MetaMask, Phantom, Coinbase Wallet, Rabby, Trust Wallet, TronLink, Ronin Wallet, Solflare, Keplr, Exodus, OKX, Rainbow, UniSat, and SafePal.

This broader browser focus suggests the operator may be seeking assets that can be monetized quickly, not only credentials for further package compromise.

The payload has a hardcoded command-and-control domain, iseekaigogo[.]com, but it can also retrieve a replacement destination through an Ethereum smart contract.

The malware queries the actor-controlled contract through public Ethereum RPC services to obtain an alternate exfiltration address. At the time of the report, the contract pointed back to the same hardcoded domain.

This dead-drop method makes blocking more difficult because the threat actor can update infrastructure without publishing a new package version.

Blockchain-based control methods

The technique resembles blockchain-based control methods documented in worm-like npm package infections, where public blockchain data is used to hide or change control infrastructure.

A particularly serious feature is the malware’s dead-man’s switch. According to Aikido, the payload can wipe infected machines when an embedded GitHub token is revoked.

That creates a difficult response situation: teams must rotate exposed credentials immediately, but they should first isolate affected devices, preserve evidence, and prepare for possible destructive behavior.

Organizations should treat any workstation, build runner, or server that installed [email protected] as fully compromised. Rotate npm, GitHub, cloud, CI/CD, SSH, Vault, browser, and wallet credentials from a clean system, then review package publishing logs and repository changes for unauthorized releases.

The response also reflects lessons from developer secret theft incidents, where stolen tokens can give malware access to many downstream projects.

Teams should remove the affected dependency, restore a known-good lockfile, rebuild environments where practical, and inspect logs for unexpected Bun downloads or execution.

Package managers and CI systems should use pinned versions, short-lived credentials, least-privilege publishing tokens, and approval controls for releases.

Security teams should also scan repositories for the named malicious files and block the listed domain at DNS, proxy, and endpoint layers.

Indicators of compromise (IoCs):-

Type Indicator Description
Compromised npm package [email protected] Malicious Tensorlake version published to npm
Command-and-control domain iseekaigogo[.]com Hardcoded control and exfiltration destination
Malicious file lib/setup.mjs Obscured preinstall-stage loader that prepares and launches Bun
SHA-256 25a0735d0db7dc40e5d45ce42d9c106067e6a66e184d967cfecfab17c3bcb5ef Hash for lib/setup.mjs
Malicious file lib/Math_Symbol.js Obscured Shai-Hulud payload executed with Bun
SHA-256 b50a00900399ba99fb6ce1fc151519cb99d44320ef2a631f2237e1aea0ad6fec Hash for lib/Math_Symbol.js
Ethereum contract / transaction indicator 0xb614155Fd88114d40549b259457Bcf921Df091B9 Actor-controlled Ethereum contract queried for an alternate C2 destination
Ethereum wallet 0x779f83aE56309682beDb04816c19d358c4B21040 Wallet associated with the September 21 contract update
Repository commit 41b38f0 Commit where the malware was introduced through direct file upload
Execution behavior node lib/setup.mjs Preinstall command used to start the malicious chain

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

The post Tensorlake npm Package Compromised to Spread Shai-Hulud Worm and Steal Developer Secrets appeared first on Cyber Security News.