Tensorlake NPM Package Compromised by Shai-Hulud Worm

NPM Package 'tensorlake' Hit by Self-Propagating Supply Chain Worm

CRITICAL
October 8, 2026
7m read
Supply Chain AttackMalwareThreat Actor

Related Entities

Organizations

Other

Shai-HuludChainDropHackBrowserData

Full Report

Executive Summary

On October 7, 2026, a critical software supply chain attack was discovered involving the tensorlake npm package. Version 0.5.144 of the package was compromised to include a self-propagating credential-stealing worm, part of the broader Shai-Hulud (also known as ChainDrop) campaign. The malware harvests a wide range of sensitive data from developer environments and CI/CD pipelines, including API keys, private keys, and cloud credentials. Its self-propagation mechanism allows it to infect other npm packages using the compromised developer's credentials, posing a significant and expanding threat to the software ecosystem. The use of a public blockchain for command-and-control (C2) makes the threat highly resilient to takedown efforts. Organizations using this package must immediately remove the malicious version, rotate all potentially exposed credentials, and audit their CI/CD environments for signs of compromise.

Threat Overview

The attack began with a malicious commit to the official tensorlakeai/tensorlake GitHub repository on October 7, 2026, pushed under a legitimate maintainer's name. A day later, the project's own release workflow published the compromised package, version 0.5.144, to the public npm registry. The package contained a preinstall hook, a script that automatically executes upon installation. This hook initiated a chain of events, starting with an obfuscated loader that used the Bun runtime to execute the primary payload: the Shai-Hulud worm.

The worm is a sophisticated information stealer designed to exfiltrate a comprehensive set of developer secrets. It targets credentials for npm, GitHub, Amazon Web Services (AWS), HashiCorp Vault, and Kubernetes, as well as SSH keys and cryptocurrency wallets. The malware also specifically searches for configuration files related to AI development tools, indicating a focused effort to compromise AI infrastructure.

Technical Analysis

The attack leverages several advanced techniques to achieve its objectives. The infection vector is a classic supply chain attack, compromising a legitimate package to distribute malware.

Attack Chain

  1. Initial Compromise: The threat actor gains access to a maintainer's account or the project's GitHub repository.
  2. Malicious Code Injection: A rogue commit adds obfuscated code and a preinstall script to the package.json file.
  3. Publication: The project's automated CI/CD pipeline builds and publishes the malicious version (0.5.144) to the npm registry.
  4. Execution: A developer or automated build system installs the compromised package, triggering the preinstall hook.
  5. Payload Deployment: The hook executes an obfuscated loader using the Bun runtime, which in turn runs the main Shai-Hulud payload.
  6. Credential Theft: The worm scans the environment for credentials, secrets, and configuration files. It also deploys the HackBrowserData binary to steal browser data.
  7. Propagation: The worm uses stolen npm and GitHub tokens to enumerate all other packages owned by the victim and republishes them with the same malicious payload. It even generates Sigstore provenance to make the new packages appear legitimate.
  8. C2 Communication: The malware communicates with its C2 infrastructure via an Ethereum smart contract, with GitHub used as a fallback mechanism. This decentralized approach makes it extremely difficult to disrupt.

MITRE ATT&CK Techniques

Impact Assessment

The impact of this attack is severe and multi-faceted. For developers and organizations that installed the malicious package, the immediate risk is the complete compromise of their development environment. The theft of AWS, Kubernetes, and HashiCorp Vault credentials could lead to a full-scale breach of cloud infrastructure, data exfiltration, and significant financial loss. The theft of cryptocurrency wallets poses a direct financial risk.

The self-propagating nature of the worm exponentially increases the attack's scope. Each compromised developer becomes a new distribution point, potentially infecting dozens of other projects and their downstream users. This creates a cascading supply chain crisis that is difficult to contain. The attack also erodes trust in the open-source ecosystem and highlights the fragility of package manager security.

IOCs — Directly from Articles

No specific file hashes, IP addresses, or domains were provided in the source articles.

Cyber Observables — Hunting Hints

Security teams may want to hunt for the following patterns to detect potential compromise:

Type
File Path
Value
**/node_modules/tensorlake/package.json
Description
Check for a preinstall script in this file for version 0.5.144.
Type
Process Name
Value
bun
Description
The Bun runtime being executed by a package manager process (npm, yarn) during installation is highly suspicious.
Type
Network Traffic
Value
Outbound connections to Ethereum nodes
Description
Monitor for unexpected traffic to public Ethereum gateways from build servers or developer machines.
Type
Log Source
Value
CI/CD pipeline logs
Description
Scrutinize logs for installations of tensorlake@0.5.144 and any subsequent anomalous behavior, such as unexpected package publications.
Type
File Name
Value
HackBrowserData
Description
The presence of this binary on a developer workstation or build agent is a strong indicator of compromise.

Detection & Response

Detection:

  1. Dependency Scanning: Use software composition analysis (SCA) tools to check for the presence of tensorlake version 0.5.144 in all projects and build environments. Tools should be configured to flag packages with preinstall scripts for manual review.
  2. Behavioral Monitoring: On CI/CD runners and developer endpoints, monitor for suspicious process chains, such as npm spawning bun. Use EDR solutions to detect the execution of unexpected binaries like HackBrowserData.
  3. Egress Filtering: Monitor and restrict outbound network traffic from build environments. Connections to cryptocurrency networks or unknown APIs should be blocked and investigated. This can help disrupt the C2 communication. (D3FEND: D3-OTF: Outbound Traffic Filtering)
  4. Log Analysis: Ingest CI/CD and version control system logs into a SIEM. Create alerts for developers publishing a large number of package updates in a short period, which could indicate automated propagation. (D3FEND: D3-SFA: System File Analysis)

Response:

  1. Isolate: Immediately isolate any system where tensorlake@0.5.144 was installed.
  2. Remove: Remove the malicious package from all projects.
  3. Credential Rotation: Assume all secrets on the affected systems are compromised. Rotate all developer tokens, API keys, SSH keys, and cloud credentials.
  4. Audit: Audit version control and package registry logs for any unauthorized package publications originating from compromised accounts.
  5. Notify: Inform downstream users of any packages that were maliciously republished by the worm.

Mitigation

Strategic:

  • Enforce Signed Commits and Packages: Use features like GitHub's signed commits and npm's package signing to ensure the integrity and provenance of code and published artifacts. (D3FEND: D3-SBV: Service Binary Verification)
  • Vet Dependencies: Implement a process for vetting new open-source dependencies before they are introduced into a project. Analyze packages for risky scripts like preinstall.
  • Principle of Least Privilege: Ensure that CI/CD pipelines and developer accounts have the minimum necessary permissions. Build processes should not have credentials capable of publishing to package registries unless explicitly required for a release.

Tactical:

  • Disable Automatic Script Execution: Configure npm to ignore preinstall and postinstall scripts by default using npm config set ignore-scripts true. Scripts can be run on a case-by-case basis after manual review.
  • Use Immutable Versions: Pin dependency versions in package-lock.json or yarn.lock to prevent unexpected updates to malicious versions.
  • Network Segmentation: Isolate build environments from the corporate network and restrict their access to the internet. (D3FEND: D3-NI: Network Isolation)

Timeline of Events

1
October 7, 2026
First rogue commit pushed to the tensorlakeai/tensorlake GitHub repository.
2
October 8, 2026
The malicious package version 0.5.144 was published to the npm registry.
3
October 8, 2026
This article was published

MITRE ATT&CK Mitigations

Enforcing package signing and verification can help prevent the installation of packages from untrusted or compromised sources.

Running build processes in isolated, ephemeral environments with restricted network access can limit the blast radius of a compromised dependency.

Configure package managers to disable or prompt for the execution of pre/post-install scripts, preventing automatic code execution.

Audit

M1047enterprise

Log all dependency changes, package installations, and network connections from build environments to detect anomalous activity.

Apply the principle of least privilege to CI/CD service accounts, ensuring they only have the permissions required for their specific tasks and cannot publish unrelated packages.

Timeline of Events

1
October 7, 2026

First rogue commit pushed to the tensorlakeai/tensorlake GitHub repository.

2
October 8, 2026

The malicious package version 0.5.144 was published to the npm registry.

Sources & References

Malicious NPM Package 'tensorlake' Hit by Self-Propagating Credential Stealer
The Hacker News (thehackernews.com) •October 8, 2026
Tensorlake's npm Package Hit with Credential-Harvesting Worm
SQ Magazine (sqmagazine.co.uk) •October 8, 2026

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

supply chainnpmshai-huludchaindropcredential theftwormdeveloper securityci/cd

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

⚡ Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.