Skip to content

Image: cdn.prod.website-files.com · rights & removal

Executive Summary

A malicious package version, 0.5.144 of the tensorlake npm package, was published on October 8, 2026. This release contained a payload from the Shai-Hulud worm family. The malicious release was distributed through the standard GitHub Actions pipeline and included valid build provenance. The malware introduced a preinstall hook that executes code upon installation before application code runs, using an obfuscated loader and a large payload file. The payload's mechanism involves harvesting credentials like npm tokens, SSH keys, and cloud access information from the host environment by probing APIs and metadata endpoints. The attacker targets secrets stored in .npmrc files, SSH keys, and cloud configurations across various platforms including AWS, GCP, and Azure.

Facts Only

* tensorlake@0.5.144 was published on 2026-10-08 01:12:07 UTC.
* Six tensorlake-native-*@0.5.144 platform binary packages were published from the same run.
* The malicious package included a preinstall hook executing node lib/setup.mjs during npm install.
* Two files, lib/setup.mjs and lib/MathSymbol.js (856 KB), carried the payload.
* The payload tagged itself with globalThis.WORMTAG='tensrlake'.
* The malware targets secrets including npm tokens, SSH keys, cloud credentials for AWS, GCP, Azure, Kubernetes, Docker configurations, and Vault tokens.
* It probes internal metadata endpoints like 169.254.169.254 to lift cloud credentials.
* Indicators of compromise include SHA256 hashes for the payload files and C2 domains such as iseekaigogo[.]com.

Full Take

The narrative of supply chain compromise hinges on the trust embedded in automated build processes. The attack leverages the established confidence in provenance—the verifiable history of a build—to mask the introduction of malicious code. The mechanism of infection shifts from simple code injection to credential harvesting, suggesting a mature threat actor focused on persistent access rather than immediate disruption. The presence of an obfuscated loader that checks for CI environment variables indicates an adaptive strategy designed to remain dormant until execution in a controlled environment. This pattern suggests a systemic risk where the very tools used for delivery—the CI/CD pipelines and package registries—are being co-opted as command and control infrastructure. The implications point toward a breakdown of trust not just within code repositories, but across the entire infrastructure stack that relies on token management and ephemeral cloud credentials. What questions remain about whether the remediation steps fully account for the potential persistence established by the harvested secrets?

From the original · Endor Labs Blog

1. Executive summary On October 8, 2026, the npm package tensorlake published version 0.5.144 carrying a malicious payload from the Shai-Hulud worm family.
Read the full story at endorlabs.com

Sentinel — Human

Confidence

The text exhibits the structure and specificity of a human-authored security bulletin analyzing a technical supply chain compromise, despite the inclusion of highly structured data.

Signals Detected
low severity: Moderate variance in sentence structure; technical reporting mixed with narrative urgency.
low severity: High internal consistency between the threat, mechanism (preinstall hook), and remediation steps.
low severity: Structured format strongly suggests a formal security advisory rather than unstructured reporting.
low severity: Specific, verifiable details (package names, commit hashes, SHA256s) are present, suggesting grounding in real artifacts.
Human Indicators
The use of highly specific, technical indicators (SHA256s, C2 domains, specific API endpoints) points toward an internal investigation or deep security reporting rather than general LLM synthesis.
The narrative flow moves logically from incident -> mechanism -> impact -> fix, characteristic of forensic reports.
Tensorlake npm package compromised by Shai-Hulud in latest software supply chain attack | Huntaegis