thehackernews.com 8 Oct 2026, 05:46 UTC

Malicious Tensorlake npm Release Steals Secrets and Spreads the Worm

CyberSIXT Evidence Panel
Threat Actor
Shai-Hulud

THE Tensorlake npm package, tensorlake, a TypeScript SDK for Tensorlake applications, sandboxes and cloud services, was compromised as part of a ChainDrop / Shai-Hulud supply chain attack. The malicious release, version 0.5.144, is no longer available on the npm registry. An analysis of the rogue release shows a preinstall hook that executes a JavaScript file (package/lib/setup[.]mjs) and an obfuscated loader that launches the main credential-stealing worm (package/lib/Math_Symbol.js) using the Bun runtime.

The malware is designed to harvest credentials across local files, CI environments, Kubernetes and Vault sources, and to drop the HackBrowserData binary, exfiltrate data, establish host persistence and execute remotely supplied code.

The campaign’s reach extends beyond a single API key; it can expose any secrets accessible to the executing process. Victims’ data types reportedly include npm and GitHub tokens, AWS credentials and secrets, HashiCorp Vault, Kubernetes credentials, SSH keys, .env files, cryptocurrency wallets, and various configuration files.

The worm propagates by enumerating packages tied to the victim’s publishing identity, creating Sigstore provenance, and republishing compromised versions, with fake Copilot/Dependabot workflows suggesting GitHub Actions workflows may also be planted.

Command-and-control relies on an Ethereum contract endpoint (iseekaigogo[.]com), with GitHub used as a fallback to stage encrypted stolen data in a public repository described as “Shai-Hulud: Here We Go Again.” A hostage token component polls the stolen GitHub token via api.github[.]com/user, and may trigger destructive PowerShell code if the token is revoked. Users who installed the malicious version should remove it and rotate credentials.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline