Skip to content
Tensorlake npm Package Compromised by Shai-Hulud Worm

Tensorlake npm Package Compromised by Shai-Hulud Worm

First seen 8 Oct 2026, 10:38 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 8, 2026 at 11:32 UTC
  • •Version 0.5.144 of Tensorlake contains a credential-stealing worm that executes on install.
  • •The malware uses a preinstall hook to run an obfuscated loader that harvests sensitive credentials.
  • •Users are advised to treat any machine that installed the compromised version as fully compromised.

On October 8, 2026, the Tensorlake npm package version 0.5.144 was compromised, delivering a credential-stealing worm known as Shai-Hulud. The malware, which was published through a compromised maintainer account, executes a preinstall hook that runs an obfuscated loader to harvest credentials from local files and CI environments. It also establishes persistence and attempts to propagate through connected supply chains. The malicious version was flagged shortly after publication, and npm has since removed it. Users who installed this version are advised to treat their machines as compromised and rotate all credentials. The attack is part of a broader trend of supply chain vulnerabilities affecting popular development tools.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-07
Malicious commits made to Tensorlake repository
The first malicious commit was made under a maintainer's name, introducing the worm payload.
Stepsecurity
2026-10-08
Compromised version 0.5.144 published to npm
Version 0.5.144 was published at 01:12:07 UTC, containing the Shai-Hulud malware.
Socket.Dev
2026-10-08
Malware flagged and removed from npm
The malicious version was flagged by security tools shortly after publication and subsequently removed.
Safedep

More articles in this cluster (7)

Following this threat?

Track Shai-hulud and Tensorlake in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions are affected?
Version 0.5.144 of the Tensorlake npm package is affected; earlier versions are not.
Is this being exploited?
Yes, the malware is actively exploiting users who installed the compromised version.
What should I do if I installed this version?
Disconnect the machine from the network, kill any persistence mechanisms, and rotate all credentials.