Overview
The tensorlake npm package — a TypeScript SDK used for Tensorlake applications, sandboxes, and cloud services — was compromised in a sophisticated supply chain attack on 7 October 2026. Version 0.5.144 contained obfuscated malware delivering the Shai-Hulud credential-stealing worm, part of a broader campaign tracked as ChainDrop. The malicious release has since been removed from the npm registry, but any developer or pipeline that installed the package during its active window faces significant exposure across credentials, secrets, and persistent attacker access.
The attack is notable for its direct targeting of AI developer tooling, including configuration files for Anthropic Claude, Cursor, Kiro, Windsurf, and Zed — tools commonly used in agentic AI and LLM-integrated development workflows.
Technical Analysis
The malicious version uses a preinstall hook to execute package/lib/setup.mjs, an obfuscated loader that invokes the core worm binary package/lib/Math_Symbol.js via the Bun JavaScript runtime.
Credential harvesting targets:
- npm and GitHub tokens
- AWS credentials and secrets
- HashiCorp Vault and Kubernetes credentials
- SSH keys and
.envfiles - Cryptocurrency wallets and messaging app data
- MCP and configuration files for Claude, Cursor, Kiro, Windsurf, and Zed
The HackBrowserData binary is dropped to extract browser-stored credentials. Exfiltrated data is staged in a public GitHub repository bearing the description “Shai-Hulud: Here We Go Again” in encrypted form.
C2 resolution is performed via an Ethereum smart contract resolving to iseekaigogo[.]com, with GitHub as a fallback. This blockchain-based C2 mechanism makes takedown significantly more difficult.
Self-propagation occurs by enumerating packages associated with the victim’s npm publishing identity, building Sigstore provenance, and republishing compromised versions. Fake Copilot/Dependabot GitHub Actions workflows are also planted to extend persistence.
The ‘hostage token’ mechanism is particularly aggressive: a PowerShell monitor continuously polls api.github.com/user with the stolen GitHub token. If the token is revoked, Invoke-Expression executes attacker-supplied PowerShell code, likely triggering a destructive payload — a tactic consistent with prior Shai-Hulud waves.
The malware also writes .claude/settings.json and .vscode/tasks.json into reachable repositories, enabling persistent code execution hooks within developer environments.
Framework Mapping
- AML.T0010 / AML.T0115: Classic AI supply chain compromise via poisoned npm artifact published under a legitimate maintainer identity.
- AML.T0083 / AML.T0098: Credential harvesting explicitly targets AI agent configuration files (MCP, Claude, Cursor), extracting secrets that could be used to impersonate or control AI agents.
- AML.T0081 / AML.T0084: Writing malicious
.claude/settings.jsonfiles constitutes modification and discovery of AI agent configuration. - LLM05: The npm supply chain vector directly matches OWASP’s Supply Chain Vulnerabilities category.
- LLM06: Mass exfiltration of secrets accessible to LLM-integrated tooling constitutes sensitive information disclosure at scale.
Impact Assessment
Any developer or automated pipeline that installed tensorlake v0.5.144 should be treated as fully compromised. Beyond the immediate credential theft, the worm’s self-propagation capability means downstream consumers of victim-maintained packages may also have been infected. The targeting of AI tool configurations (Claude, Cursor, Windsurf) extends the blast radius into agentic workflows where stolen API keys could enable model abuse or data exfiltration at the application layer.
Mitigation & Recommendations
- Remove
tensorlakev0.5.144 immediately from all environments and lock to a clean, verified version. - Rotate all credentials found in targeted locations: GitHub tokens, AWS keys, Vault secrets, SSH keys, Kubernetes configs, and AI tool API keys.
- Audit npm publish history for your maintainer identity to identify any unauthorised package releases.
- Review GitHub Actions workflows for unexpected Copilot or Dependabot workflow files.
- Scan repositories for injected
.claude/settings.jsonand.vscode/tasks.jsonfiles. - Enable npm package signing verification and monitor for Sigstore provenance anomalies.