DKDKCISSPSearch
Cloud & IdentityDEVELOPING

Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm

The npm package known as a TypeScript software development kit (SDK) for Tensorlake applications, sandboxes, and cloud services, was compromised as part of a ChainDrop / Shai-Hulud supply chain attack.

DKCISSP News DeskThe Hacker News8 Oct 2026, 12:38 pm
Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm
Image courtesy of The Hacker News. Original report
DKCISSP REPORT

The npm package known as " tensorlake ," a TypeScript software development kit (SDK) for Tensorlake applications, sandboxes, and cloud services, was compromised as part of a ChainDrop / Shai-Hulud supply chain attack.

Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud campaign .

ChainDrop was first documented in early August 2026 in connection with the compromise of hundreds of npm packages, including Keyv and Cacheable , that were found to contain a Mini Shai-Hulud variant with a self-propagating credential-stealing worm delivered through an obfuscated Bun-based JavaScript payload.

They still point to the malicious content introduced on May 18, so any workflow that references either action by a version tag resumed downloading and executing the payload on its next run." The two GitHub Actions workflows were originally compromised on May 18, 2026, to run malicious code that harvested sensitive credentials from CI/CD pipelines that ran them and exfiltrated the details to an attacker-controlled server.

The malicious version 0.5.144 "contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code," Socket said .

The activity was later linked to the Mini Shai-Hulud activity cluster, citing overlaps in the exfiltration domain ("t.m-kosche[.]com") used in the GitHub Actions workflows and the npm packages from the @antv ecosystem .

An analysis of the compromised release shows that it contains a preinstall hook designed to launch a JavaScript file ("package/lib/setup.mjs"), an obfuscated loader that launches the main credential-stealing and self-propagating worm ("package/lib/Math_Symbol.js") using the Bun runtime.

Cybersecurity researchers are calling attention to a new malware family that has been observed targeting exposed artificial intelligence (AI) and large language model (LLM) infrastructure with an aim to deploy cryptocurrency miners and further expand the scale of the botnet.

The stealer malware is designed to harvest credentials across local files, CI environments, Kubernetes, and Vault sources.

According to StepSecurity, the malicious files were pushed to the main branch of tensorlakeai/tensorlake under a maintainer's name, after which the package was released from that same repository.

What happened

The npm package known as " tensorlake ," a TypeScript software development kit (SDK) for Tensorlake applications, sandboxes, and cloud services, was compromised as part of a ChainDrop / Shai-Hulud supply chain attack.

Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud campaign .

What changed

ChainDrop was first documented in early August 2026 in connection with the compromise of hundreds of npm packages, including Keyv and Cacheable , that were found to contain a Mini Shai-Hulud variant with a self-propagating credential-stealing worm delivered through an obfuscated Bun-based JavaScript payload.

They still point to the malicious content introduced on May 18, so any workflow that references either action by a version tag resumed downloading and executing the payload on its next run." The two GitHub Actions workflows were originally compromised on May 18, 2026, to run malicious code that harvested sensitive credentials from CI/CD pipelines that ran them and exfiltrated the details to an attacker-controlled server.

Who is affected

The malicious version 0.5.144 "contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code," Socket said .

The activity was later linked to the Mini Shai-Hulud activity cluster, citing overlaps in the exfiltration domain ("t.m-kosche[.]com") used in the GitHub Actions workflows and the npm packages from the @antv ecosystem .

Why it matters

An analysis of the compromised release shows that it contains a preinstall hook designed to launch a JavaScript file ("package/lib/setup.mjs"), an obfuscated loader that launches the main credential-stealing and self-propagating worm ("package/lib/Math_Symbol.js") using the Bun runtime.

Cybersecurity researchers are calling attention to a new malware family that has been observed targeting exposed artificial intelligence (AI) and large language model (LLM) infrastructure with an aim to deploy cryptocurrency miners and further expand the scale of the botnet.

Technical details

The stealer malware is designed to harvest credentials across local files, CI environments, Kubernetes, and Vault sources.

According to StepSecurity, the malicious files were pushed to the main branch of tensorlakeai/tensorlake under a maintainer's name, after which the package was released from that same repository.

The end goal of the campaign is to weaponize known vulnerabilities in publicly exposed services to enlist them into a cryptocurrency mining botnet and convert a subset of them into a scanner to expand the victim pool.

Response

A day later, the repository's release workflow published 0.5.144 to npm.

Visiting either of the repositories now shows the message: "Access to this repository has been disabled by GitHub Staff due to a violation of GitHub's terms of service.

What security teams should do

Should the victim take steps to revoke the token, the monitor proceeds to execute an attacker-supplied handler through the "Invoke-Expression" cmdlet to execute PowerShell code designed to likely trigger a destructive routine – a tactic observed in earlier Shai-Hulud waves .

Users who have installed the malicious version are advised to remove it immediately and rotate their credentials.

Attribution

The Hacker News: The npm package known as " tensorlake ," a TypeScript software development kit (SDK) for Tensorlake applications, sandboxes, and cloud services, was compromised as part of a ChainDrop / Shai-Hulud supply chain attack.

The Hacker News: Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud campaign .

The Hacker News: Cybersecurity researchers are calling attention to a new malware family that has been observed targeting exposed artificial intelligence (AI) and large language model (LLM) infrastructure with an aim to deploy cryptocurrency miners and further expand the scale of the botnet.

MORE IN CLOUD & IDENTITY

More cybersecurity reporting

SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 AppliancesThe Hacker News · 7 Oct 2026, 9:47 pmLibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro WarningsThe Hacker News · 6 Oct 2026, 5:27 pmHacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic StealerThe Hacker News · 26 Sept 2026, 11:53 pm