Threat
Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm
First reported thehackernews.com
Page published
Earliest dated coverage: 8 Oct 2026 · First observed: 8 Oct 2026 · Latest dated coverage: 8 Oct 2026
Coverage timeline
Single-source incident — one report is available.
Why it matters
The Tensorlake compromise shows AI-service SDKs are being hijacked to spread the self-propagating Shai-Hulud credential-stealing worm, exposing developers who integrate AI tooling to automatic secret theft and persistence.
The npm package "tensorlake," a TypeScript SDK for Tensorlake AI applications, sandboxes, and cloud services, was compromised in a ChainDrop / Shai-Hulud supply-chain attack. Malicious version 0.5.144 contained an obfuscated preinstall hook that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code, per Socket; the version has since been removed from npm.