Announced 8 Oct 2026 · Sources checked
What did researchers publish on 8 October?
Socket’s research post is timestamped 02:54:50 UTC on 8 October. It says tensorlake@0.5.144 contained obfuscated malware that harvests credentials, exfiltrates secrets, persists on the host, and can run remotely supplied code. The firm says the package was published at 01:12:07 UTC and that it flagged the release 11 minutes later. Those times are Socket’s.
StepSecurity published a same-day analysis and opened GitHub issue #1014 on tensorlakeai/tensorlake at 01:22 UTC. Oliver Smith of Aikido commented at 02:13 UTC pointing at commit 41b38f0 and calling the payload a new Shai-Hulud worm; Aikido later posted its own write-up. GMO Flatt Security, The Hacker News and OX Security posted corroborating notes. This is a supply-chain report about an AI-agent SDK, closer to Lumen’s PoeLLM campaign on exposed developer tools than to a model-card update.
We opened the official issue, the named commit, the npm registry document, Tensorlake’s homepage and docs, and the researcher posts on 8 October. The issue was still open. No maintainer comment was visible on the page we fetched.
How did 0.5.144 reach npm?
The commit Aikido cited is titled “Add files via upload.” GitHub lists author cooleel, display name Shanshan Wang, and a timestamp of 03:44 UTC on 7 October. Aikido writes that the actor made verified commits under a maintainer identity and uploaded the files directly. The commit changes typescript/lib/setup.mjs and typescript/lib/Math_Symbol.js. We did not run those files.
StepSecurity writes that the first malicious commit landed on main at 01:20 UTC on 7 October, that seven more commits followed without a pull request, and that a repository release workflow published 0.5.144 at 01:12 UTC on 8 October under the same maintainer identity. It says the files in the npm tarball matched main, and that npm therefore showed a provenance attestation. An attestation records where a build ran. It does not say the code is safe.
The npm registry document we fetched lists dist-tags.latest as 0.5.143, published 6 October 21:59:43 UTC. The time map still has 0.5.144 at 01:12:07 UTC on 8 October. The versions object no longer contains 0.5.144. The package modified stamp is 02:54:27 UTC the same day. The Hacker News says 0.5.144 is no longer downloadable. We did not obtain the tarball.
What do they say the payload does?
Socket and StepSecurity describe a package.json preinstall script that runs node lib/setup.mjs. Where install scripts are allowed, that hook runs during npm install. You do not have to import the SDK or start an agent. StepSecurity says the loader skips itself on CI and targets developer machines, then downloads the Bun runtime to execute an obfuscated payload. Those are their readings of the published files.
The same posts say the worm steals npm and GitHub tokens, cloud keys, Kubernetes and Vault secrets, SSH keys, .env files, browser logins, and configuration for AI tools including Claude, Cursor and Windsurf. Flatt adds that it has seen HackBrowserData used against saved browser passwords, and AWS Secrets Manager and SSM reads across regions. OX says it found five GitHub repositories that had received stolen credentials. We did not reproduce those hunts.
Researchers also describe a hostage-token monitor named gh-token-monitor. It periodically checks a stolen GitHub token. If the token is revoked, they say the job deletes the user’s home directory — rm -rf ~/ on Unix, or a PowerShell profile wipe on Windows. Socket quotes the string IfYouRevokeThisTokenItWillWipeTheComputerOfTheOwner from earlier Shai-Hulud waves. StepSecurity says the malware can also write .claude/settings.json and .vscode/tasks.json into reachable repositories so the payload runs again when someone opens the project.
Why does an agent-sandbox SDK matter here?
Tensorlake’s homepage and docs, which we opened, describe isolated Firecracker microVMs for running untrusted or LLM-generated code, with suspend, resume and snapshots. The TypeScript SDK is how Node applications create those sandboxes. A compromised install script runs on the machine that invoked npm, with that process’s credentials, before any sandbox exists. That is the inverse of agent sandboxing: the isolation product does not protect the developer laptop that installed its client.
Socket’s “approximately 12K weekly downloads” and “over 1k stars” describe the package’s overall footprint. They are not a count of 0.5.144 installs or confirmed infections. The useful comparison is ProjectDiscovery’s backdoored coding-agent demonstration, which also starts after a credential is already on a developer host, not inside a guest VM.
OX notes the irony that a sandbox SDK is meant to contain untrusted agent code. That is commentary. The shared technical claim is simpler: treat the host that ran the install hook as compromised.
What do the researchers tell operators to do?
The overlapping advice is operational, not a new exploit. Check lockfiles and npm ls tensorlake for 0.5.144. StepSecurity and Flatt say 0.5.143 is the last clean release they inspected and that it has no preinstall script. Pin that version, delete node_modules, and clear the npm cache. Setting ignore-scripts=true stops this class of hook. We did not install either version.
If 0.5.144 ever ran on a machine, the order matters. Back up anything you cannot lose. Stop and remove gh-token-monitor first — the systemd user unit and ~/.config/gh-token-monitor/ on Linux, the LaunchAgent on macOS, the logon scheduled task on Windows. Only then revoke GitHub tokens and rotate npm, cloud, SSH, Kubernetes, Vault, .env and AI-tool secrets. Revoking the GitHub token while the monitor is still running is the step researchers say triggers the wipe. After cleanup, hunt for public repos whose description is “Shai-Hulud: Here We Go Again,” and for unexpected .claude or .vscode files. That is adjacent to GitHub’s work on detecting leaked secrets, which still assumes the secret has already been written down.
If the install happened only in CI, StepSecurity says the hook skips itself there, and still tells teams to rotate secrets that job could see. Rebuild hosts you cannot prove are clean.
What this incident does not establish
It does not establish how the publishing identity was taken over. StepSecurity describes commits under a maintainer name and a release workflow; that is not a confirmed Tensorlake infrastructure breach. Aikido says the repository was used for about 20 hours before the npm publish, and that it saw no matching PyPI or Cargo release. We found no Tensorlake blog, status page or GitHub security advisory. The issue remains open.
It does not give an infection count. Socket’s download figure is package-wide. OX’s five leaked-credential repositories are OX’s finding. We did not scan GitHub or npm for further republished packages. Researchers published file hashes and a C2 domain; take those from their posts rather than from a reprint here.
It also does not say Tensorlake’s sandboxes failed. The reported path is an npm lifecycle script on the installer. Pin 0.5.143, treat any host that ran 0.5.144 as dirty, and watch the official repository for a maintainer note that has not appeared yet.
Common questions
Is tensorlake@0.5.144 still on npm?
Not as a listed version in the registry document we opened on 8 October. latest is 0.5.143. The time map still records 0.5.144 at 01:12:07 UTC. The Hacker News says the malicious version is no longer downloadable.
Should I revoke GitHub tokens as the first step?
Not according to Socket, StepSecurity, Flatt and OX. They say remove the gh-token-monitor persistence first. Revoking the stolen token while that job is running is the trigger they describe for a home-directory wipe.
Did Tensorlake confirm the compromise?
Not in any page we found. The public record we reviewed is researcher posts, GitHub issue #1014, commit 41b38f0, and the npm registry state. The issue had no maintainer reply on the snapshot we fetched.
What to remember
Researchers say Tensorlake’s TypeScript SDK 0.5.144 was a Shai-Hulud install worm on the host that ran npm, not a sandbox escape. Pin 0.5.143, remove any token monitor before rotating credentials, and treat the missing vendor statement as a gap rather than as clearance.
Sources & further reading
- npm package tensorlake@0.5.144 contains malicious preinstall payload ↗
- tensorlake NPM package compromised with Shai Hulud worm ↗
- TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack ↗
- Tensorlake npm Package Compromised: A Worm With a Hostage Token That Wipes Your Machine If You Revoke It ↗
- tensorlake on the npm registry ↗
- Add files via upload ↗
- Software Supply Chain Attack on tensorlake: Overview and Response Guidance ↗
- Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm ↗
- “Shai-Hulud: Here We Go Again” - “tensorlake” npm Package Hit With Malware ↗
- Sandbox and Orchestration Infrastructure for Agents ↗
- Tensorlake — Sandboxes for AI Agents ↗
How this story was made
Written by Kristian Kostov with AI assistance and checked against the linked sources. Company performance claims are attributed to the company. Analysis reflects AiLookout’s interpretation; we have not independently tested the products discussed. Cover photography is illustrative and does not depict the specific announcement or product.
Our editorial standards





