Skip to content
“Shai-Hulud: Here We Go Again” - “tensorlake” npm Package Hit With Malware

“Shai-Hulud: Here We Go Again” - “tensorlake” npm Package Hit With Malware

Ox.Security • October 8, 2026

Breaking News: Shai-Hulud malware affecting “tensorlake” package version 0.5.144,

A malicious version of tensorlake (version 0.5.144) was published to npm with Shai-Hulud malware.

The malware also contains an Ethereum contract address, which is tied to a wallet containing 12.44$ worth of crypto currency.

Threat actors used new public keys that differ from other attacks. This may indicate an independent threat actor or a new group using the Shai-Hulud name and malicious code.

Anyone who installed or ran [email protected]

Do not revoke the stolen GitHub token before isolating the machine. Disconnect the host from the network and kill the gh-token-monitor persistence first (see IOCs). Otherwise, revocation triggers rm -rf ~/ (Windows: Remove-Item $env:USERPROFILE -Recurse -Force). Then rotate your keys.

Treat every machine that installed it as fully compromised. Rotate all GitHub, npm, cloud, Vault, SSH and CI secrets reachable from it.

Hunt for the IOCs below across GitHub (branches, workflow files, commits) and endpoints (persistence, network).

Inside the code we detected this Ethereum contract address – 0xb614155Fd88114d40549b259457Bcf921Df091B9 which maps to this wallet – 0x779f83aE56309682beDb04816c19d358c4B21040

When examining the wallet, we can see that the account currently holds 12.44$, and was created 16 days ago.

Additionally, we can see in GitHub that 5 repositories have been uploaded with stolen credentials following this recent attack.

The malware contains heavy obfuscation, with multiple decode functions and hash functions to extract its own strings to memory when running.

Public encryption keys are newly seen, and are not connected to any of the Shai-Hulud variants we’ve seen in the past.

MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAsx7qQlP6BjB14dud92Hk

MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAmSsAhtZtB2S7XBxe5Ofr

The malware’s revoke kill-switch string is the same one that was used in the TanStack attack back in May – IfYouRevokeThisTokenItWillWipeTheComputerOfTheOwner:

The malware contains infostealer logic, browser data stealing logic, crypto draining, cloud configuration stealing, environment variable stealing and many more.

Shai-Hulud is yet again attacking AI and agentic frameworks, and in an ironic turn of events, a Sandbox for AI, the type of package that’s trying to prevent attacks and malwares like Shai-Hulud spreading in the wild.

Shai-Hulud variants keep breaking the assumption that we’ve learned our lesson and that our package managers and registries will be safe week. Apparently, they won’t be.

The Shai-Hulud name, hardcoded in the malware’s source code, has outlived its TeamPCP origins. Group members were arrested in August. The name now works as a brand that copycats reuse.

Now, every Shai-Hulud reference becomes more of a statement, an almost poetic one, an ode to a group of threat actors that took over packages with billions of downloads all around the world.

Ethereum contract 0xb614155Fd88114d40549b259457Bcf921Df091B9

WORMTAG = “tensrlake”

IfYouRevokeThisTokenItWillWipeTheComputerOfTheOwner

thebeautifulmarchoftime

Shai-Hulud: Here We Go Again

Add Copilot workflow, chore: update dependencies

setup.mjs, .claude/setup.mjs, .vscode/setup.mjs, .claude/settings.json, .vscode/tasks.json

Math_Symbol.js, math_init.js, opensearch_init.js, ai_init.js

~/.local/bin/gh-token-monitor.sh, ~/.config/gh-token-monitor/

~/.config/systemd/user/gh-token-monitor.service

~/Library/LaunchAgents/com.user.gh-token-monitor.plist

Windows scheduled task gh-token-monitor; %LOCALAPPDATA%\gh-token-monitor

Malicious dependency vetting

The above package and future variants of this malicious campaign are included in the OX security malware database.

OX customers using VibeSec trying to install one of the malicious packages will be blocked by the platform and an alternative safe package will be suggested to them.

OX customers pushing code with the malicious package as dependency will also be blocked by the OX platform pipeline scan .