Threat

Shai-Hulud worm makes jump to AI infrastructure with Tensorlake compromise

Page published · Page updated

Dossier

Earliest dated coverage: 8 Oct 2026 · First observed: 8 Oct 2026 · Latest dated coverage: 8 Oct 2026

Coverage timeline

8 Oct 2026theregister.com

Single-source incident — one report is available.

Why it matters

The Shai-Hulud worm's jump to an AI agent platform SDK shows supply-chain malware now targets AI infrastructure directly, compromising developer and build hosts before any sandbox protections apply and threatening cascading credential theft across the ecosystem.

The self-propagating, credential-stealing Shai-Hulud worm compromised version 0.5.144 of Tensorlake's npm SDK, a package with roughly 12,000 weekly downloads used to create and manage Tensorlake AI agent environments. Researchers at Socket and SafeDep report the variant (sharing code with the ChainDrop strain) steals crypto wallets, browser passwords, GitHub Actions secrets, cloud credentials and service-account tokens, maintains a C2 channel, and can delete an infected user's home directory if a monitored GitHub token is revoked. The malicious install script runs outside Tensorlake's sandbox, on developer machines or build servers.

campaign

Summary

The credential-stealing, self-propagating Shai-Hulud worm compromised version 0.5.144 of Tensorlake's npm SDK, marking a jump of the npm supply-chain worm into AI agent infrastructure. The package is popular (~12,000 weekly downloads, 1,000+ GitHub stars), raising the risk to anyone who installed the malicious version.[0]

The malicious release shares code and techniques with the earlier Shai-Hulud variant dubbed ChainDrop, which was used in August to compromise npm packages including keyv and flat-cache. It steals a broad range of secrets—crypto wallets, browser passwords, GitHub Actions secrets, cloud credentials, and service-account tokens—exfiltrates them, and maintains a C2 channel for further instructions.[0]

Socket detected the infection 11 minutes after publication; npm removed the version and Tensorlake pulled the package, releasing 0.5.145. Despite the short exposure window, the overall impact remains unknown, and a destructive token-monitoring capability can delete an infected user's home directory if affected credentials are revoked improperly.[0][1]

Attack chain

  1. Initial Compromise / Supply-Chain Delivery: A malicious, worm-infected release of Tensorlake's npm SDK (version 0.5.144) was published to the npm registry, delivering Shai-Hulud to developers who installed the package.[0]
  2. Execution: The malicious SDK's installation script executes on the developer's machine or build server—outside Tensorlake's sandbox protections—inheriting the permissions of the installing process and potentially compromising the host before any AI-generated code runs.[0]
  3. Credential Theft / Collection: The worm harvests credentials and secrets including crypto wallets, browser passwords, GitHub Actions secrets, cloud credentials, and service-account tokens.[0]
  4. Exfiltration and Command-and-Control: Stolen data is exfiltrated and the worm keeps an open line to its C2 infrastructure to await further instructions.[0]
  5. Propagation and Destructive Impact: Like other Shai-Hulud variants, the worm self-propagates. It also monitors certain stolen GitHub tokens and, if one is revoked under specific conditions, can trigger deletion of the infected user's home directory, complicating removal.[0]

Disclosure timeline

DateEvent
2026-08-15The related Shai-Hulud variant ChainDrop was reported compromising npm dependencies including keyv and flat-cache.[0]
2026-10-08 (morning UTC)The infected Tensorlake SDK version 0.5.144 was published to npm.[0]
2026-10-08Socket flagged the malicious version 11 minutes after publication; npm removed it, and Tensorlake pulled the package and released version 0.5.145.[0][1]

How it works

This is not a software vulnerability but a supply-chain malware infection. The compromised npm SDK carries an installation script that executes automatically during package install on a developer workstation, application server, or build runner—outside Tensorlake's sandbox. The executed code inherits the permissions of the installing process, allowing it to access deployment credentials and other secrets on the host before any AI-generated code is run.[0]

The worm's credential-stealing payload collects crypto wallets, browser passwords, GitHub Actions secrets, cloud credentials, and service-account tokens, exfiltrates them, and keeps a C2 channel open for further instructions. A token-monitoring component watches certain stolen GitHub tokens and, under specific conditions when a token is revoked, can trigger deletion of the infected user's home directory.[0]

Affected versions and patch status

ProductAffectedPatch status
Tensorlake npm SDKVersion 0.5.144Malicious version removed from npm and pulled by Tensorlake; fixed in version 0.5.145.[0][1]

Indicators of Compromise

TypeIndicatorContext
othertensorlake npm SDK 0.5.144Malicious, Shai-Hulud-infected release of the Tensorlake npm SDK; defenders should check whether this version was installed.[0]

Key takeaways

  • The Shai-Hulud npm supply-chain worm has expanded into AI agent infrastructure by compromising the popular Tensorlake SDK, showing that AI platform tooling is now a target for credential-stealing supply-chain worms.[0]
  • Sandbox isolation of AI-generated code does not protect against malicious SDK install scripts, which run on developer and build hosts and inherit their permissions and access to deployment secrets.[0]
  • Rapid detection (11 minutes) and package removal limited exposure, but impact remains unknown and the worm's destructive token-monitoring behavior makes remediation order critical.[0]

Defensive actions

  • Verify whether the malicious Tensorlake SDK version 0.5.144 was installed and upgrade to 0.5.145.: The infected version was published and briefly available on npm; Tensorlake and npm removed it, and 0.5.145 is the clean release.[0][1]
  • Rebuild compromised systems from a trusted source before restoring access to secrets.: Socket recommends rebuilding compromised systems because the worm can compromise the install host and persist.[0]
  • Disable the malicious token monitor before revoking affected credentials.: The variant monitors stolen GitHub tokens and can trigger deletion of the infected user's home directory if a token is revoked, so researchers warn the monitor must be neutralized first.[0]
  • Rotate exposed secrets—crypto wallets, browser passwords, GitHub Actions secrets, cloud credentials, and service-account tokens.: The worm is designed to steal and exfiltrate these credentials, so any potentially exposed secrets should be rotated.[0]