Tensorlake npm Compromise Spreads Credential-Stealing Worm With Destructive Token Monitor
The npm package tensorlake version 0.5.144 was compromised with install-time malware that steals developer credentials and browser data and attempts to spread through npm packages and GitHub repositories. StepSecurity reported that malicious commits were pushed directly to tensorlakeai/tensorlake under a maintainer identity, after which the repository’s release workflow published the package with a valid npm provenance attestation. Aikido identified the payload as a Shai-Hulud worm variant and assessed it as likely a new compromise rather than reinfection from an earlier wave. The malware skips CI environments, targets developer machines, and establishes persistence through Claude Code and VS Code configuration files. It exfiltrates encrypted secrets through attacker-created public GitHub repositories or iseekaigogo.com, with command-and-control discovery using Ethereum transaction data.
- Sonatype reveals public GitHub exfiltration fallback in Tensorlake malware
- Tensorlake updates SDK to version 0.5.145 after withdrawing compromised release


