Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > Compromised Tensorlake npm Release Spreads Shai-Hulud Worm Through Developer Systems
Compromised Tensorlake npm Release Spreads Shai-Hulud Worm Through Developer Systems
Read Time:3 Minute, 7 Second

A compromised release of the Tensorlake package on npm has delivered a new Shai-Hulud worm variant designed to steal developer secrets and expand through software supply chains. The malicious version, tensorlake@0.5.144, appeared on October 8 and is particularly concerning because package installation itself triggers the payload.

Tensorlake provides serverless sandboxing for AI agents, and its npm package has accumulated more than 100,000 lifetime installs. That figure does not reveal how many systems installed the malicious build, but it illustrates the trust and potential reach associated with the package. Researchers at Aikido reported no evidence that Tensorlake’s PyPI or Cargo distributions were affected at the time of their analysis.

A Preinstall Script Starts the Infection

The malicious chain begins with a package preinstall command that launches node lib/setup.mjs. The obscured loader downloads the legitimate Bun JavaScript runtime and uses it to execute a second file, lib/Math_Symbol.js, containing the primary payload. Using a newly fetched runtime may help the activity avoid controls focused on conventional Node.js execution.

Aikido traced the malicious files to a verified commit made with a maintainer identity on October 7. The payload was added through a direct file upload and remained in the repository for roughly 20 hours before the tainted npm version was released. Researchers found a distinctive WORMTAG marker and assessed the incident as a fresh Tensorlake compromise rather than an accidental repeat of a previous infection wave.

Once active, the malware searches broadly for useful credentials. Targets include environment variables, SSH material, cloud configuration, Docker and Kubernetes credentials, Vault tokens, CI/CD secrets, GitHub data, and local browser profiles. It also inspects extension databases associated with numerous cryptocurrency wallets, suggesting both supply-chain expansion and direct financial theft are objectives.

Blockchain Data Provides a Backup Control Channel

The payload contains the hardcoded domain iseekaigogo[.]com for command and exfiltration traffic. It can also query an attacker-controlled Ethereum smart contract through public RPC services to obtain a replacement destination. At the time of the report, the contract returned the same domain, but the mechanism would allow the operator to redirect infected hosts without publishing another package.

The malware also reportedly contains destructive behavior tied to an embedded GitHub token. If that token is revoked, a dead-man’s switch may wipe infected machines. This creates a response dilemma: credentials need rapid rotation, yet hasty action on the compromised host could destroy evidence or data. Isolation and evidence preservation should therefore precede remediation where possible.

Installed Version 0.5.144 Requires Incident Response

Any workstation, build runner, or server that installed tensorlake@0.5.144 should be treated as fully compromised. Simply removing the dependency is insufficient because secrets may already have been copied and publishing credentials could have enabled unauthorized changes elsewhere.

  • Disconnect affected systems while preserving volatile and disk evidence.
  • From a known-clean device, rotate npm, GitHub, cloud, CI/CD, SSH, Vault, browser, and wallet credentials.
  • Review package publication records, repository commits, workflow changes, and downstream releases.
  • Hunt for the two malicious files, unexpected Bun downloads, the command domain, and the reported Ethereum contract.
  • Restore a trusted lockfile and rebuild affected environments rather than assuming local cleanup is complete.

Longer-term controls should include pinned dependency versions, short-lived credentials, tightly scoped publishing tokens, protected release workflows, and approval gates for package publication. Organizations should also monitor install-time scripts and outbound connections from build systems. Trusted dependency mirrors can add a useful review point before a newly published version reaches production pipelines. This incident shows why developer infrastructure deserves the same containment, credential hygiene, and telemetry as production: one stolen maintainer identity can convert a trusted dependency into an attack path reaching many unrelated environments.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on Compromised Tensorlake npm Release Spreads Shai-Hulud Worm Through Developer Systems, use the discussion on Forum.

>> forum community

Comments

Leave a Reply