Critical Tensorlake npm Package Flaw Spreads Shai-Hulud Worm, Steals Dev Secrets
Key Takeaways A critical vulnerability in the Tensorlake npm package (version 0.5.144) has led to the spread of a new Shai-Hulud worm variant. The malware targets developer secrets, including cloud...
Key Takeaways
- A critical vulnerability in the Tensorlake npm package (version 0.5.144) has led to the spread of a new Shai-Hulud worm variant.
- The malware targets developer secrets, including cloud credentials, CI/CD tokens, SSH keys, and cryptocurrency wallet data.
- The compromise leverages a sophisticated evasion technique by using the Bun JavaScript runtime and a blockchain-based command-and-control mechanism.
- A “dead-man’s switch” feature allows the attackers to wipe infected machines if a specific GitHub token is revoked, complicating incident response.
- Developers using
[email protected]should consider their systems fully compromised and immediately initiate a comprehensive incident response.
A malicious version of the Tensorlake npm package has been released, embedding a new variant of the Shai-Hulud worm. This sophisticated malware is designed to exfiltrate sensitive developer secrets and propagate through interconnected software supply chains, posing a significant threat to development environments.
Table Of Content
The compromised package, identified as [email protected], was published on October 8, 2026. Tensorlake, a serverless sandbox platform for AI agents, boasts over 100,000 lifetime installs for its npm package, highlighting the potential breadth of this supply chain attack. Investigations at the time of analysis by Analysts from Aikido identified no signs of compromise in the package’s PyPI and Cargo distributions, focusing the incident on the npm ecosystem.
This event underscores the persistent danger posed by compromised dependencies, which can serve as direct conduits into developer workstations, CI/CD pipelines, cloud infrastructure, and package publishing accounts. Unlike traditional phishing, this attack requires no user interaction beyond installing the malicious package; the malware activates during installation, before any intended use of the library.
The operational tactics observed in this incident align closely with previous Shai-Hulud worm campaigns. These attacks often exploit stolen package publishing credentials, transforming a single compromised development environment into a cascading supply-chain threat.
Tracing the Compromise
Analysts from Aikido identified the malicious Tensorlake release and confirmed its payload as a distinct Shai-Hulud variant, rather than a mere re-infection from an earlier wave. Researchers noted that the malicious code establishes a unique global WORMTAG marker before executing its hidden logic, indicating a fresh compromise of the Tensorlake package.
The malware was introduced into the project’s GitHub repository on October 7, when an attacker made verified commits using a maintainer’s identity. The payload was specifically added via a malicious file upload in commit 41b38f0. The repository remained compromised for approximately 20 hours before the malicious npm package was officially published.
Tensorlake npm Package Compromised
The infection chain initiates with a preinstall script that invokes node lib/setup.mjs. This script is heavily obfuscated and proceeds to download the Bun JavaScript runtime. It then utilizes Bun to execute lib/Math_Symbol.js, which contains the primary Shai-Hulud payload. The strategic use of Bun represents a significant evasion technique, as many security systems are configured to monitor Node.js activity more closely than a newly introduced runtime environment. This tactic mirrors other Bun-based npm malware campaigns, where legitimate developer runtimes are exploited to bypass script-focused security checks.
Once active, the malware systematically harvests sensitive data. It targets secrets stored in environment variables, local credential files, cloud configurations (including AWS access keys, Kubernetes configurations, and Azure data), CI/CD systems, Docker, Kubernetes, SSH folders, Vault tokens, and GitHub-related data. Furthermore, it specifically seeks out browser profiles and extension databases associated with popular cryptocurrency wallets, such as MetaMask, Phantom, Coinbase Wallet, Rabby, Trust Wallet, TronLink, Ronin Wallet, Solflare, Keplr, Exodus, OKX, Rainbow, UniSat, and SafePal. This broad focus on cryptocurrency assets suggests the threat actor’s intent to quickly monetize stolen data, alongside gaining deeper access to development infrastructure.
The payload incorporates a hardcoded command-and-control (C2) domain, iseekaigogo[.]com. However, it also possesses the capability to retrieve an alternative C2 destination by querying an Ethereum smart contract. The malware communicates with this actor-controlled contract via public Ethereum RPC services to obtain an updated exfiltration address. At the time of reporting, the contract directed traffic back to the original hardcoded domain. This “dead-drop” mechanism significantly complicates blocking efforts, as the threat actor can modify their infrastructure without issuing a new, compromised package version.
Blockchain-based Control Methods
This technique of leveraging public blockchain data to conceal or alter control infrastructure is consistent with other documented worm-like npm package infections. A particularly alarming feature of this malware is its “dead-man’s switch.” According to Aikido’s analysis, the payload can initiate a full wipe of infected machines if an embedded GitHub token is revoked. This introduces a critical dilemma for incident responders: while exposed credentials must be rotated immediately, organizations must first isolate affected devices, preserve forensic evidence, and prepare for potential destructive actions.
Organizations must consider any workstation, build runner, or server that installed [email protected] as fully compromised. A thorough response involves rotating all npm, GitHub, cloud, CI/CD, SSH, Vault, browser, and wallet credentials from a clean, untainted system. Additionally, reviewing package publishing logs and repository changes for any unauthorized releases is crucial.
This incident also highlights broader lessons from developer secret theft incidents, where compromised tokens can grant malware access to numerous downstream projects. Teams should remove the affected dependency, restore a known-good lockfile, rebuild environments where feasible, and meticulously inspect logs for any unexpected Bun downloads or execution.
To bolster defenses, package managers and CI systems should enforce pinned versions, utilize short-lived credentials, implement least-privilege publishing tokens, and establish stringent approval controls for all releases. Security teams should further scan repositories for the identified malicious files and block the listed command-and-control domain at DNS, proxy, and endpoint levels.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Compromised npm package | [email protected] |
Malicious Tensorlake version published to npm |
| Command-and-control domain | iseekaigogo[.]com |
Hardcoded control and exfiltration destination |
| Malicious file | lib/setup.mjs |
Obscured preinstall-stage loader that prepares and launches Bun |
| SHA-256 | 25a0735d0db7dc40e5d45ce42d9c106067e6a66e184d967cfecfab17c3bcb5ef |
Hash for lib/setup.mjs |
| Malicious file | lib/Math_Symbol.js |
Obscured Shai-Hulud payload executed with Bun |
| SHA-256 | b50a00900399ba99fb6ce1fc151519cb99d44320ef2a631f2237e1aea0ad6fec |
Hash for lib/Math_Symbol.js |
| Ethereum contract / transaction indicator | 0xb614155Fd88114d40549b259457Bcf921Df091B9 |
Actor-controlled Ethereum contract queried for an alternate C2 destination |
| Ethereum wallet | 0x779f83aE56309682beDb04816c19d358c4B21040 |
Wallet associated with the September 21 contract update |
| Repository commit | 41b38f0 |
Commit where the malware was introduced through direct file upload |
| Execution behavior | node lib/setup.mjs |
Preinstall command used to start the malicious chain |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
What You Should Do
- Isolate and Contain: Immediately isolate any system that installed
[email protected]. Do not simply remove the package, as the “dead-man’s switch” could trigger a wipe. - Preserve Evidence: Create forensic images of affected systems before any remediation to preserve evidence.
- Rotate Credentials: From a known clean system, rotate all associated credentials, including npm tokens, GitHub personal access tokens, cloud provider keys (AWS, Azure), CI/CD system credentials, SSH keys, Vault tokens, and browser/wallet credentials.
- Remove Malicious Dependency: After isolation and credential rotation, remove
[email protected]from all projects. - Restore and Rebuild: Restore environments to a known-good state using a clean lockfile and rebuild where practical.
- Monitor for Anomalies: Scrutinize logs for unexpected Bun downloads or execution, and for unauthorized package publishing or repository changes.
- Network Blocking: Block the command-and-control domain
iseekaigogo[.]comat your DNS, proxy, and endpoint security layers. - Enhance Supply Chain Security: Implement strict measures like pinned package versions, short-lived and least-privilege publishing tokens, and mandatory approval workflows for all package releases.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.