Tensorlake npm Compromise: Shai-Hulud Targets AI Agent SDKs

Authors: Cloud Security Alliance AI Safety Initiative
Published: 2026-10-10

Categories: Supply Chain Security
Download PDF

Tensorlake npm Compromise: Shai-Hulud Targets AI Agent SDKs

Key Takeaways

On October 8, 2026, a malicious release of the tensorlake npm package, version 0.5.144, was published to the registry. The package is the TypeScript SDK for Tensorlake, a platform that provides sandboxes and cloud services for AI applications and agents. Security vendors attribute the payload to the Shai-Hulud worm family and associate it with a campaign they call ChainDrop [1][2]. Socket’s automated scanning flagged the release roughly eleven minutes after publication, and the version has since been removed from npm [1][3].

Three features of this incident matter most for defenders. First, the payload executes from a preinstall hook, so it runs when the package is installed, before any application code imports the SDK [1]. Second, it collects configuration files for AI coding tools (including Claude, Cursor, and Zed) together with the cloud, CI, and registry credentials that AI agent infrastructure typically holds [1][2]. Third, it carries a “hostage token” mechanism that monitors a stolen GitHub token and can trigger destructive commands on the victim’s machine if the token is revoked [1][2]. This note does not assert that these features are new to the Shai-Hulud family; the hostage token is the one with the most direct effect on the order of operations for incident response.

The compromise also illustrates a limit of provenance controls. Endor Labs reports that the malicious version retained valid Sigstore provenance, because the malicious change was committed to the source repository before the trusted build pipeline ran [4]. Provenance in this case established where the build came from, not whether the source was clean. Teams that rely on attestations as their primary trust signal should reassess that reliance.

Recommended actions, covered in detail below, are to block and search for 0.5.144, to remove persistence before revoking any credential, to rotate secrets from any host that ran the install, and to disable install-time lifecycle scripts where the build allows it.

Background

Shai-Hulud is the name given to a family of self-propagating npm worms that steal publishing credentials from developer machines and CI systems and use them to republish malicious versions of every package the victim can publish. CSA has tracked the family through several waves in 2026. Its earlier research notes document the worm lineage’s focus on AI developer toolchains, and the simultaneous emergence of the Miasma and IronWorm worms, both aimed at AI coding tool credentials [5][6]. The July 2026 jscrambler compromise showed a related infostealer reaching for MCP server tokens and AI assistant credentials [7].

Tensorlake’s SDK fits that pattern of target selection. Socket reports roughly 12,000 weekly downloads and more than 1,000 GitHub stars for the package, [1]. Its position matters more than its size. An SDK for agent sandboxes is installed by developers and build systems that tend to hold cloud credentials, model provider keys, and repository publishing rights in the same environment. A compromise of such a package therefore reaches machines that are likely to be rich in secrets, which appears to suit a credential-harvesting worm, although the vendors do not establish the attacker’s intent.

The public reporting describes the following sequence. The dates below combine details from several vendors, and they do not agree on every point, as noted after the table.

Date (UTC) Event Source
September 21, 2026 Threat actor updates an Ethereum contract with a command-and-control address later used by the payload [3]
October 7, 2026, ~01:20 First malicious commit pushed to the main branch of the tensorlake repository under a verified maintainer identity [2][3][4]
October 8, 2026, 01:12:07 Version 0.5.144 published to npm [1][4]
October 8, 2026, 01:23:10 Socket flags the release, about eleven minutes after publication [1]
October 8, 2026 Version removed from npm; advisories published [1][2][4]

Aikido describes the gap between the malicious commit and the npm publication as roughly twenty hours, while the timestamps in the other reports imply a gap closer to twenty-four hours [3][4]. The reports do not explain the difference. Aikido’s and Endor Labs’ accounts also cite different commit identifiers for the first malicious change, so this note does not reproduce either [3][4]. Readers who need exact forensic timing should consult the repository history and the vendors’ current advisories. Aikido reports that only the npm package was affected as of its report, with no corresponding compromise found in the Python distribution [3]; that negative finding is time-bound and should be confirmed against current advisories. All incident detail in this note comes from vendor blogs and press reporting, and no statement from Tensorlake or its maintainers is cited.

Security Analysis

Initial access and the provenance problem

The most likely root cause, according to the reporting, is control of a maintainer’s GitHub identity. The attacker was able to push commits that appeared as verified and that landed directly on the main branch [2][3]. The reports do not establish how that access was obtained, and this note does not speculate beyond the vendors’ statements. What the sources do establish is that the subsequent release flowed through the project’s normal build and publication path. Endor Labs observes that this is why the package carried valid Sigstore provenance: the attestation correctly recorded that the artifact was built from the repository, and the repository itself was already poisoned [4].

CSA’s earlier analysis of the AI package registry ecosystem reported an earlier case of malicious packages carrying valid SLSA Build Level 3 provenance, which it described as evidence that process-integrity controls can be defeated at the build pipeline level [8]. The attestation types differ (SLSA Build Level 3 there, Sigstore here), but taken together the two cases suggest that provenance is best treated as one signal about build integrity, and that it provides little protection when an attacker controls the identity authorized to change the source. Branch protection, mandatory review by a second maintainer, and phishing-resistant authentication on maintainer accounts address that gap more directly than attestation checks.

Execution chain and targeted data

The package’s manifest added a preinstall script that runs node lib/setup.mjs. Socket describes this file as an obfuscated loader that launches the main payload, lib/Math_Symbol.js, using the Bun runtime [1]. Endor Labs reports that the payload is about 856 KB and that it contains a worm marker string [4]. The use of an install-time hook means the payload runs on any machine or CI job that resolves the compromised version, including transitive installs where no developer ever imported the SDK. Socket published SHA-256 hashes for both files, and Aikido lists the same values together with the related Ethereum contract address [1][3].

The reporting lists a broad set of targets. Socket and Endor Labs describe collection of npm tokens and OIDC exchanges, GitHub tokens and CLI configuration, AWS credentials (including instance metadata, ECS, Secrets Manager, and SSM sources), other cloud provider credentials, HashiCorp Vault tokens, Kubernetes service accounts, Docker configuration, SSH keys, .env files, and cryptocurrency wallets [1][4]. Both The Hacker News and Socket add configuration files for AI coding tools, naming Claude, Cursor, and Zed; the lists differ between sources, and individual reports also mention other editors such as Windsurf, Kiro, and VS Code [1][2]. On CI runners, Endor Labs reports that the payload checks environment variables such as CI and GITHUB_ACTIONS and downloads a secondary stage [4]. For AI agent infrastructure the practical consequence is that model provider keys, MCP server tokens, and agent configuration sit in the same places as the cloud and registry credentials the worm already hunts for, and a single install can expose all of them.

Persistence and the hostage token

According to Socket, the payload installs a PowerShell-based monitor through an on-logon scheduled task, and the monitor polls GitHub’s API with a stolen token to detect revocation [1]. If revocation is detected, an attacker-supplied handler executes through Invoke-Expression, and the code contains a literal string warning that revoking the token will wipe the owner’s computer [1]. The Hacker News describes the destructive action as wiping the home directory [2]. Socket’s remediation guidance for Windows, Linux, and macOS accordingly lists removal of the persistence mechanism as a step that precedes credential revocation: deleting the scheduled task on Windows, disabling the service on Linux, and removing the LaunchAgent on macOS [1].

The reports also describe persistence inside repositories. The Hacker News states that the malware writes .claude/settings.json and .vscode/tasks.json files into repositories, which would let configuration files for AI coding tools and editors re-run attacker commands even after the npm package is removed [2]. Socket notes that references to fake Copilot and Dependabot workflows suggest the ability to inject GitHub Actions workflows [1]. These details matter because removing the dependency does not remove the foothold. Teams that have to clean affected repositories should review these file types, along with unexpected workflow files, as part of the investigation.

Command and control, and propagation

Socket reports that the payload contains no hardcoded domains and resolves endpoints through roughly thirty public Ethereum RPC endpoints, falling back to GitHub [1]. The sources do not fully agree on this point: Aikido reports a primary command-and-control domain (iseekaigogo[.]com) alongside the Ethereum contract [3], and The Hacker News lists an additional primary exfiltration endpoint on a domain registered for the campaign and describes staging of stolen data in public GitHub repositories whose descriptions reference an earlier Shai-Hulud wave [2]. Resolving the controller address through a blockchain contract means that blocking a single domain may not interrupt the malware, and that takedowns of a single domain are unlikely to be sufficient to disrupt it, although the GitHub fallback channel can be reported and removed. Network defenders may still find value in monitoring for unexpected connections to public Ethereum RPC providers from build hosts and developer workstations, which have little ordinary reason to make them.

The worm propagates by enumerating packages tied to the victim’s publishing identity, injecting the payload, generating Sigstore provenance, and republishing [1][4]. The effect is that a single infected maintainer machine can seed further compromises, each of which may also carry attestations. Socket places this incident in a wider pattern, noting similar behavior in August 2026 compromises of the keyv and cacheable packages, and The Hacker News associates the campaign with the removal of 77 malicious extensions from the Open VSX marketplace [1][2]. CSA’s June 2026 analysis of the registry ecosystem counted 37 distinct supply chain campaigns across npm and PyPI in 2026 to date [8], which is consistent with a sustained trend in which this incident does not stand alone.

Why AI agent tooling raises the stakes

AI agent platforms concentrate three properties that make them attractive for this class of worm. Their SDKs are installed in development and CI environments with broad credentials. They are adopted quickly, often with little review of the dependency graph. And the machines that run them often store configuration for several AI tools and MCP servers in plaintext files that a lifecycle script can read. CSA’s earlier notes on Miasma, IronWorm, and jscrambler describe the same dynamic of AI tool configurations being targeted alongside conventional credentials [6][7]. The Tensorlake case adds an agent infrastructure SDK as the delivery vehicle, which means the attacker’s initial foothold sits inside the toolchain organizations are adopting to build agents.

Recommendations

Immediate Actions

Teams should search lockfiles, dependency manifests, build caches, and container images for tensorlake@0.5.144, and block that version in internal registries and proxies. Endor Labs advises pinning to 0.5.143 and purging references to 0.5.144 from lockfiles [4]. Any host or CI job that installed the version should be treated as fully compromised, and the system should be isolated before remediation begins.

Order of operations matters because of the hostage token. On affected hosts, responders should first identify and remove the persistence mechanism (the scheduled task, service, or LaunchAgent) and should preserve a forensic copy where feasible, and only then revoke the exposed GitHub token and other credentials [1]. Revoking first risks triggering the destructive handler on a machine that is still running the monitor. Once persistence is removed, rotate npm, GitHub, SSH, cloud, Vault, Kubernetes, and model provider credentials from the affected environment, and rotate AI tool and MCP tokens stored in the configuration files the payload targeted [1][4].

Responders should then audit the accounts that were reachable from the host for unexpected repository creation, newly added workflow files, and package publications, since these are the worm’s propagation signals [2][4]. Review repositories for unauthorized .claude/settings.json, .vscode/tasks.json, and workflow files [2]. Rebuild affected systems from trusted sources instead of cleaning them in place [1].

Short-Term Mitigations

Where the build allows it, run installs with npm install --ignore-scripts or an equivalent organization-wide setting, and enable lifecycle scripts only for packages that require them [4]. This control blocks the preinstall vector used here, although CSA’s jscrambler analysis notes that later variants of that campaign moved their droppers from lifecycle scripts into the package’s main code [7]. Script blocking should therefore be paired with other controls, not relied on alone.

In this incident, Socket flagged the malicious version within minutes and it was removed the same day [1], so a minimum release age policy of even one or two days for new package versions would likely have avoided exposure. Detection times vary across campaigns, so a release-age delay should be treated as one control among several. Teams should also remove long-lived publishing tokens from developer workstations in favor of short-lived, scoped credentials, and should require phishing-resistant authentication for maintainers of any package they publish. Egress controls on build and CI hosts, including monitoring for connections to public Ethereum RPC endpoints, add a detection path that does not depend on a package scanner.

Strategic Considerations

Organizations that build AI agents should maintain an inventory of the SDKs, MCP servers, and registry packages their agents and developer environments depend on, with named owners and an update policy. Agent-hosting SDKs should be treated as privileged dependencies, since they run alongside the credentials the agents use. Running agent SDK installs in isolated CI runners that hold no publishing credentials, and separating credentials by environment, limits what any single install can reach. Model provider keys and MCP tokens are better kept in a secrets manager or OS keychain than in plaintext configuration files on developer machines, which the payload here was shown to read.

Organizations that publish packages should assume that valid provenance can accompany a malicious release and should add controls on the source side: protected branches, required second-party review of changes to release workflows and manifests, and monitoring of release-related changes by newly active or newly privileged identities. Consumers should treat attestations as supporting evidence and combine them with behavioral analysis and release-age policies [4][8].

CSA Resource Alignment

CSA has published several notes on the worm family involved here, and they provide the closest context for this incident. The research note Shai-Hulud: npm Worm Targeting AI Developer Toolchains documents the family’s earlier targeting of AI developer toolchains [5]. The Tensorlake payload’s collection of AI coding tool configuration files appears to continue that pattern, and the earlier note’s guidance is a useful starting point for this incident.

CSA’s research note Miasma and IronWorm: Self-Replicating Worms Targeting AI Credentials examines two self-replicating npm worms that emerged in June 2026 with shared references to the Shai-Hulud lineage and a focus on AI coding tool credentials [6]. It supports the view that the lineage persists through multiple variants and actors. The related note jscrambler npm Compromise: IronWorm Targets AI Dev Credentials is relevant to the mitigation guidance above, because it shows an attacker moving a dropper out of the preinstall script to defeat controls that inspect lifecycle scripts only [7].

At the ecosystem level, AI Package Registry Crisis: Unguarded Critical Infrastructure places incidents like this one within the broader registry threat picture and reports the first instance of malicious packages carrying valid SLSA Build Level 3 provenance [8]. Its findings on provenance limits are directly relevant to the Sigstore behavior observed in this incident, and its discussion of registry-level controls supports the strategic considerations above.

References

[1] Socket. “TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack.” Socket, October 2026.

[2] The Hacker News. “tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm.” The Hacker News, October 2026.

[3] Aikido Security. “tensorlake NPM package compromised with Shai Hulud worm.” Aikido, October 8, 2026.

[4] Endor Labs. “tensorlake npm package compromised by Shai-Hulud in latest software supply chain attack.” Endor Labs, October 2026.

[5] Cloud Security Alliance AI Safety Initiative. “Shai-Hulud: npm Worm Targeting AI Developer Toolchains.” CSA Labs, May 2026.

[6] Cloud Security Alliance AI Safety Initiative. “Miasma and IronWorm: Self-Replicating Worms Targeting AI Credentials.” CSA Labs, June 2026.

[7] Cloud Security Alliance AI Safety Initiative. “jscrambler npm Compromise: IronWorm Targets AI Dev Credentials.” CSA Labs, July 2026.

[8] Cloud Security Alliance AI Safety Initiative. “AI Package Registry Crisis: Unguarded Critical Infrastructure.” CSA Labs, June 2026.

← Back to Research Index