Back Aikido.Dev tensorlake NPM package compromised with Shai Hulud worm
On 8 October 2026 a threat actor published a compromised version of tensorlake to npm. The compromised version is 0.5.144 and contains a variant of the Shai-Hulud worm, which exfiltrates secrets from infected devices and attempts to self-replicate through connected supply chains. Tensorlake is a serverless sandbox for AI agents and its npm package has a reported lifetime install count of over 100,000.
Tensorlake also distributes a package via PyPI and Cargo, but there is no sign the threat actor has been able to publish to either ecosystem at the time of writing. The malware contains slight variations from the last Shai-Hulud wave, so it is likely part of a novel compromise rather than ongoing reinfection.
What the malware does
The malware is triggered via a preinstall script, which invokes node lib/setup.mjs . setup.mjs ( 25a0735d0db7dc40e5d45ce42d9c106067e6a66e184d967cfecfab17c3bcb5ef ) is an obfuscated script that serves to drop Bun to an infected host and to execute lib/Math_Symbol.js ( b50a00900399ba99fb6ce1fc151519cb99d44320ef2a631f2237e1aea0ad6fec ) with the Bun runtime.
Math_Symbol.js contains an obfuscated Shai-Hulud payload. The malware sets a global WORMTAG marker before executing obfuscated code, specific to the infected tensorlake package. This marker indicates that the package is a novel compromise rather than an ongoing reinfection from a prior Shai-Hulud wave.
The malware decrypts persistence and proliferation payloads and a dead-man's switch that wipes infected machines if an embedded GitHub token is revoked, consistent with prior Shai-Hulud waves . Also consistent with prior Shai-Hulud waves, the malware attempts to read and exfiltrate sensitive environment variables and local secrets. A full index of the data targeted by the malware is available at the end of this post. Any system or environment infected by the malware should be treated as fully compromised and any secrets or credentials it contained should be rotated as a critical priority.
The malware contains the hardcoded C2 address iseekaigogo[.]com , but also contains a blockchain dead-drop mechanism to resolve an alternate C2. The malware calls a read function on the threat actor-controlled Ethereum contract
0xb614155Fd88114d40549b259457Bcf921Df091B9 through eth.llamarpc.com , rpc.ankr.com and ethereum.publicnode.com to retrieve an alternative C2/exfiltration domain. The most recent update to the contract, made on 21 September from the wallet 0x779f83aE56309682beDb04816c19d358c4B21040 , sets this value to the same hardcoded C2 address, iseekaigogo[.]com .
Tracing the infection
The malware originated from the tensorlake GitHub repository. On 7 October 2026, the threat actor made verified commits under the identity of a maintainer. The malware was introduced in commit 41b38f0 via direct file upload, after which the threat actor attempted to bump versions and trigger publishing. The repository was compromised for approximately 20 hours before the threat actor was able to trigger the npm publish.
How Aikido detects this
If you are an Aikido user, check your central feed and filter on malware issues. This will surface as a 100/100 critical issue. Aikido rescans nightly, but we recommend triggering a manual rescan now.
If you are not yet an Aikido user, you can create an account and connect your repos. Our malware coverage is included in the free plan, no credit card required.
For broader coverage across your whole team, Aikido's Device Protection gives you visibility and control over the software packages installed on your team's devices. It covers browser extensions, code libraries, IDE plugins, and build dependencies, all in one place. Stop malware before it gets installed.
For future protection, consider Aikido Safe Chain (open source). Safe Chain sits in your existing workflow, intercepting npm, npx, yarn, pnpm, and pnpx commands and checking packages against Aikido Intel before install.
Indicators of compromise
lib/setup.mjs 25a0735d0db7dc40e5d45ce42d9c106067e6a66e184d967cfecfab17c3bcb5ef
25a0735d0db7dc40e5d45ce42d9c106067e6a66e184d967cfecfab17c3bcb5ef
lib/Math_Symbol.js b50a00900399ba99fb6ce1fc151519cb99d44320ef2a631f2237e1aea0ad6fec
b50a00900399ba99fb6ce1fc151519cb99d44320ef2a631f2237e1aea0ad6fec
Threat actor Ethereum transaction: 0xb614155Fd88114d40549b259457Bcf921Df091B9
0xb614155Fd88114d40549b259457Bcf921Df091B9
Threat actor Ethereum wallet: 0x779f83aE56309682beDb04816c19d358c4B21040
0x779f83aE56309682beDb04816c19d358c4B21040
Targeted variables and files
Environment variables:
Credential file paths:
Get secure today, quickly and for free.
Secure your code, cloud, and runtime in one central system. Connect a repo to discover what the reasoning agents find in your codebase.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
