Skip to content
Tensorlake npm package compromised by Shai-Hulud in latest software supply chain attack

Tensorlake npm package compromised by Shai-Hulud in latest software supply chain attack

Endorlabs • October 8, 2026

The popular Tensorlake SDK, a package with more than 12,000 weekly downloads and 1000 GitHub starts shipped a poisoned release (version 0.5.144 ) that was infected with the self-propagating Shai-Hulud worm.

On October 8, 2026, the npm package tensorlake published version 0.5.144 carrying a malicious payload from the Shai-Hulud worm family. The package is the official TypeScript SDK for Tensorlake and is widely used, so this is a real supply chain risk for anyone who installed that specific version.

The malicious release shipped through the project's normal GitHub Actions pipeline and even carried valid build provenance. Provenance confirms where a build came from, not that the source was clean. In this case the attacker modified the project's main branch first, then let the trusted pipeline publish the result. The most likely root cause is a compromised maintainer account, which is the signature behavior of Shai-Hulud.

The bad version has since been removed from npm, and the version 0.5.143 is clean. If you installed 0.5.144, treat any credential on that machine as exposed and rotate it.

tensorlake@0.5.144 (npm). Published 2026-10-08 01:12:07 UTC. Now removed from the registry.

The six tensorlake-native-*@0.5.144 platform binary packages were published from the same run. They contain only the native binary and no install script, and we found no payload in them, but they should still be treated as part of the affected release and avoided.

Not affected: tensorlake@0.5.143 and earlier. These do not contain the preinstall hook or the payload files.

3. Technical analysis

What it does. The attacker added a preinstall hook to the package manifest that runs node lib/setup.mjs. Because npm runs preinstall before anything else, the code executes automatically on npm install, before any of your own application code. Two files were added to carry the payload: a small obfuscated loader (lib/setup.mjs) and a large obfuscated payload (lib/Math_Symbol.js, 856 KB). The payload is tagged internally with a marker string, globalThis.WORMTAG='tensrlake', which is how the worm labels each package it infects.

How it spreads and steals. This family works by stealing a developer's npm and GitHub credentials, then using those credentials to republish itself into other packages the victim controls and to create repositories that hold the stolen data. The loader checks whether it is running in CI (it inspects variables like CI, GITHUB_ACTIONS, GITLAB_CI, and RUNNER_ENVIRONMENT) and then pulls down and runs a second stage. The payload reaches out to the GitHub API and the npm registry to harvest tokens, propagate, and exfiltrate.

What it targets. The payload hunts for a broad set of secrets, including npm tokens (.npmrc), SSH keys, cloud credentials for AWS, GCP, and Azure, Kubernetes and Docker configuration, HashiCorp Vault tokens, CI and registry tokens, GitHub CLI config, and environment files such as .env. On cloud hosts it also probes internal metadata endpoints to lift short lived cloud credentials.

Block and avoid tensorlake@0.5.144. Pin to 0.5.143 until a known good release is published.

Remove any lockfile entries and package caches that reference 0.5.144, then reinstall from clean sources.

If 0.5.144 was installed anywhere, especially in CI, assume credential theft. Rotate npm tokens, GitHub tokens and SSH keys, cloud keys, and any secrets that were present on that host.

Review recent GitHub and npm activity for unexpected repository creation, new tokens, or unexpected publishes under affected accounts.

Consider installing with scripts disabled by default (for example npm install --ignore-scripts) in environments where that is practical, since the payload relies on a preinstall hook.

5. Indicators of compromise

lib/setup.mjs: 25a0735d0db7dc40e5d45ce42d9c106067e6a66e184d967cfecfab17c3bcb5ef

lib/Math_Symbol.js: b50a00900399ba99fb6ce1fc151519cb99d44320ef2a631f2237e1aea0ad6fec

0xb614155Fd88114d40549b259457Bcf921Df091B9 - ETH resolver wallet (EtherHiding). On-chain dead-drop the malware reads to fetch the current C2 domain. Durable indicator.

iseekaigogo[.]com - C2 domain. Daemon POSTs victim host/user/os. Disposable, rotated on-chain.

URLs and services abused

(used for credential checks, repository creation, and spread)

(used for token checks, OIDC token exchange, maintainer lookup, and republishing)

Source repository: first malicious commit e90c47bbb2 (2026-10-07 01:20 UTC)

Release run that published the package:

IPs and internal endpoints probed (legitimate infrastructure targeted for credential theft, not attacker servers)

169.254.169.254 (cloud instance metadata, for example AWS IMDS)

169.254.170.2 (container and ECS task credentials)

127.0.0.1:8200 (local HashiCorp Vault)

When you're ready to take the step in securing your software supply chain, here are 3 ways Endor Labs can help: