www.stepsecurity.io 8 Oct 2026, 02:09 UTC

Poisoned npm Package Steals Developer Secrets and Threatens File Wipe

CyberSIXT Evidence Panel Source marked as original reporting

STEPSECURITY has disclosed a supply chain incident centred on the npm package tensorlake@0.5.144, released on 8 October 2026. The release appears to have been built from the project’s own main branch, with a provenance attestation attached to the npm package. The researchers report that the source repository was poisoned directly in its main branch, with payload files committed through the GitHub web UI under a maintainer account and released under that identity.

The package, when installed, activates a preinstall hook that fetches the Bun runtime and executes a heavily obfuscated 856 KB payload. The payload is designed to exfiltrate credentials stored on development machines—GitHub and npm tokens, cloud keys, Kubernetes and Vault secrets, SSH keys, browser logins, and configuration files for AI coding tools—and to transmit them in encrypted form. It also uses stolen npm and GitHub tokens to propagate to other packages and repositories.

Three features set this incident apart: first, the attack surface extends beyond the npm package to the poisoned source repo itself; second, a so‑called Hostage Token monitors the stolen GitHub token and, if token usage is blocked, triggers a wipe of the user’s home directory (rm -rf ~/ on Unix-like systems, or a PowerShell equivalent on Windows); and third, it targets AI coding agents, injecting hooks into AI tooling configurations and VS Code tasks to reinfect or propagate further.

The researchers advise pinning tensorlake to 0.5.143 and, if 0.5.144 was installed, removing the token monitor before rotating credentials. Investigations are ongoing, with plans to publish a full analysis, indicators of compromise, and remediation steps. The organisation responsible disclosed the finding responsibly to the tensorlake maintainers via GitHub issue #1014.

View full article

Article by CyberSIXT