Threat

Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm

Page published

Earliest dated coverage: 8 Oct 2026 · First observed: 8 Oct 2026 · Latest dated coverage: 8 Oct 2026

Coverage timeline

8 Oct 2026thehackernews.com

Single-source incident — one report is available.

Why it matters

The Tensorlake compromise shows AI-service SDKs are being hijacked to spread the self-propagating Shai-Hulud credential-stealing worm, exposing developers who integrate AI tooling to automatic secret theft and persistence.

The npm package "tensorlake," a TypeScript SDK for Tensorlake AI applications, sandboxes, and cloud services, was compromised in a ChainDrop / Shai-Hulud supply-chain attack. Malicious version 0.5.144 contained an obfuscated preinstall hook that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code, per Socket; the version has since been removed from npm.