On October 7, 2026, a critical software supply chain attack was discovered involving the tensorlake npm package. Version 0.5.144 of the package was compromised to include a self-propagating credential-stealing worm, part of the broader Shai-Hulud (also known as ChainDrop) campaign. The malware harvests a wide range of sensitive data from developer environments and CI/CD pipelines, including API keys, private keys, and cloud credentials. Its self-propagation mechanism allows it to infect other npm packages using the compromised developer's credentials, posing a significant and expanding threat to the software ecosystem. The use of a public blockchain for command-and-control (C2) makes the threat highly resilient to takedown efforts. Organizations using this package must immediately remove the malicious version, rotate all potentially exposed credentials, and audit their CI/CD environments for signs of compromise.
The attack began with a malicious commit to the official tensorlakeai/tensorlake GitHub repository on October 7, 2026, pushed under a legitimate maintainer's name. A day later, the project's own release workflow published the compromised package, version 0.5.144, to the public npm registry. The package contained a preinstall hook, a script that automatically executes upon installation. This hook initiated a chain of events, starting with an obfuscated loader that used the Bun runtime to execute the primary payload: the Shai-Hulud worm.
The worm is a sophisticated information stealer designed to exfiltrate a comprehensive set of developer secrets. It targets credentials for npm, GitHub, Amazon Web Services (AWS), HashiCorp Vault, and Kubernetes, as well as SSH keys and cryptocurrency wallets. The malware also specifically searches for configuration files related to AI development tools, indicating a focused effort to compromise AI infrastructure.
The attack leverages several advanced techniques to achieve its objectives. The infection vector is a classic supply chain attack, compromising a legitimate package to distribute malware.
preinstall script to the package.json file.0.5.144) to the npm registry.preinstall hook.Bun runtime, which in turn runs the main Shai-Hulud payload.HackBrowserData binary to steal browser data.T1195.002 - Compromise Software Supply Chain: The core of the attack involves injecting malicious code into a legitimate software package.T1059.007 - JavaScript/TypeScript: The malware is executed via npm's preinstall hook, which runs a JavaScript-based payload.T1555.003 - Credentials from Web Browsers: The use of the HackBrowserData tool indicates theft of credentials stored in web browsers.T1552.004 - Private Keys: The malware specifically targets SSH keys and cryptocurrency wallets.T1134 - Access Token Manipulation: Stolen npm and GitHub tokens are used to propagate the worm.T1071.004 - DNS: While using a blockchain, the underlying principle is similar to using a non-standard protocol for C2 resolution, making it a form of Application Layer Protocol abuse.The impact of this attack is severe and multi-faceted. For developers and organizations that installed the malicious package, the immediate risk is the complete compromise of their development environment. The theft of AWS, Kubernetes, and HashiCorp Vault credentials could lead to a full-scale breach of cloud infrastructure, data exfiltration, and significant financial loss. The theft of cryptocurrency wallets poses a direct financial risk.
The self-propagating nature of the worm exponentially increases the attack's scope. Each compromised developer becomes a new distribution point, potentially infecting dozens of other projects and their downstream users. This creates a cascading supply chain crisis that is difficult to contain. The attack also erodes trust in the open-source ecosystem and highlights the fragility of package manager security.
No specific file hashes, IP addresses, or domains were provided in the source articles.
Security teams may want to hunt for the following patterns to detect potential compromise:
**/node_modules/tensorlake/package.jsonpreinstall script in this file for version 0.5.144.bunBun runtime being executed by a package manager process (npm, yarn) during installation is highly suspicious.CI/CD pipeline logstensorlake@0.5.144 and any subsequent anomalous behavior, such as unexpected package publications.HackBrowserDataDetection:
tensorlake version 0.5.144 in all projects and build environments. Tools should be configured to flag packages with preinstall scripts for manual review.npm spawning bun. Use EDR solutions to detect the execution of unexpected binaries like HackBrowserData.D3-OTF: Outbound Traffic Filtering)D3-SFA: System File Analysis)Response:
tensorlake@0.5.144 was installed.Strategic:
D3-SBV: Service Binary Verification)preinstall.Tactical:
npm config set ignore-scripts true. Scripts can be run on a case-by-case basis after manual review.package-lock.json or yarn.lock to prevent unexpected updates to malicious versions.D3-NI: Network Isolation)Enforcing package signing and verification can help prevent the installation of packages from untrusted or compromised sources.
Running build processes in isolated, ephemeral environments with restricted network access can limit the blast radius of a compromised dependency.
Configure package managers to disable or prompt for the execution of pre/post-install scripts, preventing automatic code execution.
Log all dependency changes, package installations, and network connections from build environments to detect anomalous activity.
Apply the principle of least privilege to CI/CD service accounts, ensuring they only have the permissions required for their specific tasks and cannot publish unrelated packages.
First rogue commit pushed to the tensorlakeai/tensorlake GitHub repository.
The malicious package version 0.5.144 was published to the npm registry.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.