Image: cdn.prod.website-files.com · rights & removal
Executive Summary
Facts Only
* tensorlake@0.5.144 was published on 2026-10-08 01:12:07 UTC.
* Six tensorlake-native-*@0.5.144 platform binary packages were published from the same run.
* The malicious package included a preinstall hook executing node lib/setup.mjs during npm install.
* Two files, lib/setup.mjs and lib/MathSymbol.js (856 KB), carried the payload.
* The payload tagged itself with globalThis.WORMTAG='tensrlake'.
* The malware targets secrets including npm tokens, SSH keys, cloud credentials for AWS, GCP, Azure, Kubernetes, Docker configurations, and Vault tokens.
* It probes internal metadata endpoints like 169.254.169.254 to lift cloud credentials.
* Indicators of compromise include SHA256 hashes for the payload files and C2 domains such as iseekaigogo[.]com.
Full Take
From the original · Endor Labs Blog
1. Executive summary On October 8, 2026, the npm package tensorlake published version 0.5.144 carrying a malicious payload from the Shai-Hulud worm family.Read the full story at endorlabs.com
Sentinel — Human
The text exhibits the structure and specificity of a human-authored security bulletin analyzing a technical supply chain compromise, despite the inclusion of highly structured data.
