A threat actor published a malicious version of the tensorlake npm package on October 8, 2026, embedding a new variant of the self-replicating Shai-Hulud supply-chain worm.
The compromised release, tensorlake version 0.5.144, can steal developer secrets, target browser-stored cryptocurrency credentials, and use stolen publishing credentials to spread through connected software supply chains.
The incident highlights the growing risk to AI-development tooling: a dependency compromise can expose not only application build environments but also cloud credentials, source-control tokens, deployment secrets, and agent-development workflows.
The malicious package activates through a preinstall lifecycle hook that invokes node lib/setup.mjs.
The obfuscated setup.mjs, identified by SHA-256 25a0735d0db7dc40e5d45ce42d9c106067e6a66e184d967cfecfab17c3bcb5ef, downloads the Bun runtime and uses it to execute lib/Math_Symbol.js.
The second-stage file, SHA-256 b50a00900399ba99fb6ce1fc151519cb99d44320ef2a631f2237e1aea0ad6fec, contains the obfuscated credential-stealing and worm-propagation payload.
The malware sets a package-specific WORMTAG marker before launching its encrypted logic.
That implementation distinguishes the Tensorlake incident from reinfection during an earlier Shai-Hulud campaign and points to a separate, newly seeded compromise.
Previous Shai-Hulud activity spread rapidly after attackers abused maintainer access and npm credentials to republish poisoned packages; one August campaign reportedly affected at least 444 packages and 1,381 versions.
Once executed, the payload attempts to collect environment variables, local secret files, npm tokens, GitHub credentials, cloud credentials, SSH keys, Kubernetes configuration, Terraform files, Docker registry credentials, and CI/CD secrets.
Such access creates an immediate downstream risk: stolen npm publishing tokens may enable the worm to modify packages maintained by victims, while compromised GitHub credentials can provide access to repositories and automated release pipelines.
Earlier Shai-Hulud variants also targeted GitHub Actions runners and OIDC tokens used in package-publishing workflows.
Aikido Researchers said that, Tensorlake is a serverless sandbox platform for AI agents, and its npm package has recorded more than 100,000 lifetime installs.
Tensorlake Package Hijacked
The Tensorlake payload includes a dead-man’s switch that can wipe infected systems if an embedded GitHub token is revoked, a mechanism previously observed in Shai-Hulud operations.
It also uses the hardcoded command-and-control domain iseekaigogo[.]com and can retrieve a replacement C2 or exfiltration address from Ethereum smart contract 0xb614155Fd88114d40549b259457Bcf921Df091B9.
The malware queries the contract through public RPC services including eth.llamarpc.com, rpc.ankr.com, and ethereum.publicnode.com.
The wallet 0x779f83aE56309682beDb04816c19d358c4B21040 last updated the contract on September 21, setting the alternate value to the same iseekaigogo[.]com domain.
A significant evolution is the campaign’s apparent focus on browser-resident financial data.
The malware searches hardcoded paths associated with 14 cryptocurrency browser extensions and attempts to steal IndexedDB and LevelDB data.
It also downloads and executes a platform-appropriate HackBrowserData utility from its C2 infrastructure to extract additional credentials from browser stores.
This behavior suggests operators may be prioritizing direct monetization from compromised developer endpoints alongside supply-chain propagation.
Investigators traced the initial intrusion to Tensorlake’s GitHub repository. On October 7, an attacker made verified commits using a maintainer identity and introduced the malicious files in commit 41b38f0 through a direct upload.
The repository remained compromised for roughly 20 hours before the actor successfully initiated the malicious npm publication.
Tensorlake’s PyPI and Cargo distributions showed no indication of compromise at the time of reporting.
Organizations should immediately identify installations of [email protected], isolate potentially affected hosts, preserve forensic evidence, and rotate all credentials accessible from those systems.
This includes npm and GitHub tokens, cloud keys, CI/CD secrets, SSH keys, API credentials, cryptocurrency wallet-extension data, and browser-session tokens.
Teams should also review package publishing histories, GitHub audit logs, CI runner activity, and unexpected changes to package.json lifecycle scripts.
The case follows earlier Shai-Hulud attacks in which malicious preinstall scripts downloaded Bun and executed heavily obfuscated JavaScript payloads to harvest secrets and propagate through npm ecosystems.
IOCs
| Indicator Type | Value |
|---|---|
| npm package | tensorlake |
| Package version | 0.5.144 |
| C2 domain | iseekaigogo[.]com |
| File path | lib/setup.mjs |
| File hash (as provided) | 25a0735d0db7dc40e5d45ce42d9c106067e6a66e184d967cfecfab17c3bcb5ef |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.

