Tensorlake npm Package Compromised to Spread Shai-Hulud Credential Stealer
A malicious release of tensorlake, a TypeScript SDK used to build applications, sandboxes, and cloud services on the Tensorlake platform, has been caught distributing a self-propagating credential-stealing worm tied to the ongoing Shai-Hulud / ChainDrop supply-chain campaign.
What happened
Version 0.5.144 of the package shipped with a preinstall hook that silently launched an obfuscated loader, which in turn executed a credential-harvesting worm using the Bun runtime. The malicious version has since been pulled from the npm registry.
Once active, the malware swept up a wide range of sensitive material from the host: npm and GitHub tokens, AWS credentials, HashiCorp Vault secrets, Kubernetes credentials, SSH keys, .env files, cryptocurrency wallets, messaging-app data, and — notably — configuration and MCP files tied to AI coding assistants including Claude Code, Cursor, Kiro, Windsurf, and Zed. It also deployed a browser-data extraction tool to pull stored credentials directly from local browsers.
The worm didn't stop at theft. It enumerated other packages tied to the victim's publishing identity and attempted to republish trojanized versions of them, spreading the compromise further downstream. Investigators also found that it dropped lookalike GitHub Actions workflow files and wrote startup files into .claude and .vscode project folders, so the malware would re-trigger the next time a developer opened an infected project in Claude Code or VS Code.
For command-and-control, the malware resolved its endpoint through an Ethereum smart contract, with a public GitHub repository as a fallback channel for staging stolen data. It also included a "hostage token" mechanism: if a victim revoked the stolen credentials, the malware could trigger a destructive PowerShell routine — a tactic consistent with earlier Shai-Hulud campaigns.
The rogue code was pushed to the package's source repository under a legitimate maintainer's identity before being published to npm, underscoring how maintainer account compromise continues to be the primary delivery path for these attacks.
Why it matters
This incident extends the Shai-Hulud/ChainDrop campaign — previously tied to hundreds of compromised packages — into a new target: the tooling developers use to build and run AI agents. Credentials and configuration files for AI coding assistants are increasingly valuable to attackers, since they can expose access to connected cloud services, repositories, and MCP-integrated systems. A single compromised dependency can therefore cascade into stolen cloud credentials, poisoned CI/CD pipelines, and further propagation across the npm ecosystem — all before anyone notices the package behaved abnormally.
What to do
- Check your dependency tree for
tensorlakeversion0.5.144and remove it immediately if present. - Rotate every credential that could have been exposed on affected hosts: npm and GitHub tokens, cloud (AWS) keys, Vault secrets, Kubernetes credentials, SSH keys, and any secrets in
.envfiles. - Audit
.claudeand.vscodeproject folders for unexpected task or settings files that could re-trigger malicious code. - Review GitHub Actions workflows in affected repositories for unfamiliar or lookalike entries.
- Enforce provenance and integrity checks (e.g., Sigstore verification, lockfile pinning) in your build pipeline, and monitor for unexpected outbound connections from CI/build environments.
