Skip to content
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential

TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential

Socket.Dev •Socket Research Team • October 8, 2026

Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Socket detected a compromised release of tensorlake , the npm SDK for Tensorlake’s AI agent infrastructure, in a ChainDrop / Shai-Hulud supply chain attack. Version 0.5.144 contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code. The package receives approximately 12K weekly downloads and has over 1k stars on GitHub .

Tensorlake provides isolated sandboxes for running untrusted, LLM-generated code, with checkpointing, suspend, and resume capabilities. Its npm SDK lets developers create and manage those environments from TypeScript applications. A compromised SDK creates exposure on the machine installing it, before generated code reaches a sandbox.

The malicious version was published on October 8, 2026, at 01:12:07 UTC . Socket flagged it at 01:23:10 UTC , approximately 11 minutes after publication .

A preinstall hook launches the malicious code #

The affected release’s published package manifest contains a preinstall hook:

Where dependency lifecycle scripts are permitted, this hook gives the malicious loader an execution path during installation. Developers do not need to import the SDK or start an agent for the hook to run.

Socket flagged two files in the published package:

package/lib/setup.mjs — An obfuscated loader invoked by the preinstall hook that launches the payload using Bun.

package/lib/Math_Symbol.js — The obfuscated credential-stealing and self-propagating worm payload.

Socket’s initial assessment identifies credential harvesting across local files, CI environments, Kubernetes, and Vault sources. The malicious code also exfiltrates collected data, establishes persistence, and supports execution of remotely supplied code.

That combination extends the risk beyond a single stolen API key. Any secrets accessible to the executing process may be exposed, and persistence can retain attacker access after the affected dependency is removed.

ChainDrop reaches AI agent infrastructure #

The installation hook and payload filenames match the structure documented in the August ChainDrop / Shai-Hulud compromises of keyv , cacheable , and related npm packages. In that campaign, a setup.mjs loader executed an obfuscated Math_Symbol.js payload, and stolen publishing credentials enabled the worm to spread to additional packages.

The Tensorlake compromise brings that attack pattern into tooling used to build and operate AI agents. Teams may isolate an agent’s generated code while installing its SDK on a developer workstation, application server, or build runner with access to deployment credentials and other secrets. Code executed during that installation inherits the permissions of the installing process.

The 12K weekly download figure describes the package’s overall usage. It does not measure downloads of the malicious version or confirmed infections.

The payload steals credentials and spreads through npm #

The payload is a broad credential stealer and self-propagating worm. Its collection targets include:

npm tokens: .npmrc files, the npm token API, and the OIDC token exchange.

GitHub tokens: Tokens checked for repository and workflow permissions.

AWS credentials and secrets: Instance Metadata Service (IMDS), ECS, Secrets Manager, and Systems Manager Parameter Store (SSM).

HashiCorp Vault: Local instances at 127.0.0.1:8200 , including Kubernetes and AWS authentication paths.

Kubernetes credentials: Service-account tokens and kubeconfig files.

Other sensitive files: SSH keys, .env files, cryptocurrency wallets, and messaging app data.

AI development tools: Configuration and MCP files associated with .claude , .cursor , .kiro , Windsurf, and Zed.

To propagate, the worm enumerates packages associated with the victim’s publishing identity, builds Sigstore provenance, and republishes compromised versions. Strings referencing a fake Copilot/Dependabot workflow suggest it also plants GitHub Actions workflows.

An Ethereum contract resolves the remote endpoint #

The payload has no hardcoded command-and-control domain. Instead, it resolves its endpoint through an Ethereum contract using approximately 30 public RPC endpoints, with a GitHub fallback. This matches the resolver design reported in the keyv compromise.

A dead-man switch reacts to token revocation #

The “hostage token” component uses a PowerShell monitor that persists through an ONLOGON scheduled task. It polls api.github.com/user using the stolen GitHub token to check whether the token remains valid.

When the token is revoked, the monitor executes an attacker-supplied handler through Invoke-Expression . The code also contains the literal string IfYouRevokeThisTokenItWillWipeTheComputerOfTheOwner , previously seen in earlier Shai-Hulud waves.

Remove the affected release and investigate exposed hosts #

Teams using Tensorlake should check dependency manifests, lockfiles, build logs, and deployed artifacts for [email protected] .

Block the affected version and prevent further installation.

Identify environments where its installation scripts ran. Treat hosts where the malicious code executed as compromised.

Isolate affected hosts and investigate persistence. Removing the npm dependency alone does not remove a persistent implant.

Remove the token monitor before revoking any tokens. On each affected host, stop and delete the gh-token-monitor persistence Linux: systemctl --user disable --now gh-token-monitor.service and remove ~/.config/gh-token-monitor/ macOS: unload ~/Library/LaunchAgents/com.user.gh-token-monitor.plist Windows: delete the ONLOGON scheduled task running monitor.ps1

Linux: systemctl --user disable --now gh-token-monitor.service and remove ~/.config/gh-token-monitor/

macOS: unload ~/Library/LaunchAgents/com.user.gh-token-monitor.plist

Windows: delete the ONLOGON scheduled task running monitor.ps1

Only after the step revoke and replace exposed credentials. Revoking the stolen GitHub token while the monitor is still running triggers the dead-man switch to wipe the user's directory, regardless of where the revocation is done.

Audit connected accounts for unauthorized access, unexpected package publications, and changes to repositories or deployment systems.

Rebuild affected environments from trusted sources and use a verified clean release before restoring access to secrets.

Indicators of Compromise #

Malicious npm Package #

File: lib/setup.mjs SHA-256: 25a0735d0db7dc40e5d45ce42d9c106067e6a66e184d967cfecfab17c3bcb5ef

File: lib/Math_Symbol.js SHA-256: b50a00900399ba99fb6ce1fc151519cb99d44320ef2a631f2237e1aea0ad6fec