The npm package tensorlake version 0.5.144 was compromised with install-time malware that steals developer credentials and browser data and attempts to spread through npm packages and GitHub repositories. StepSecurity reported that malicious commits were pushed directly to tensorlakeai/tensorlake under a maintainer identity, after which the repository’s release workflow published the package with a valid npm provenance attestation. Aikido identified the payload as a Shai-Hulud worm variant and assessed it as likely a new compromise rather than reinfection from an earlier wave. The malware skips CI environments, targets developer machines, and establishes persistence through Claude Code and VS Code configuration files. It exfiltrates encrypted secrets through attacker-created public GitHub repositories or iseekaigogo.com, with command-and-control discovery using Ethereum transaction data.
A background service named gh-token-monitor checks a GitHub token every 60 seconds for up to 24 hours and deletes the user’s home directory if GitHub rejects the token, making credential revocation potentially destructive while the monitor remains active. Affected organizations should remove the monitor before revoking credentials, treat infected systems as fully compromised, and then urgently rotate exposed credentials. StepSecurity recommends pinning tensorlake to 0.5.143 and investigating repository modifications and other propagation indicators. Aikido found no evidence of malicious publishing to PyPI or Cargo. The compromised release demonstrates that valid package provenance can accompany malicious code when the source repository and its authorized release path are compromised.

Trace attribution and downstream blast radius.
12 events from the most recent confirmed update back to the earliest known activity.
Socket flagged tensorlake@0.5.144 at 01:23:10 UTC, approximately 11 minutes after publication. Its analysis linked the malware to ChainDrop/Shai-Hulud through similarities in payload filenames, Ethereum-based endpoint resolution, and token-monitoring code seen in earlier compromises.
The repository's release workflow published tensorlake@0.5.144 at 01:12 UTC under the same maintainer identity. The release contained the malicious repository files and carried a valid npm provenance attestation despite containing malware.
Seven additional commits followed over the next few hours, modifying the payload and adding a preinstall hook to package.json. Aikido identified direct malware upload in commit 41b38f0, followed by attempts to bump versions and trigger publication.
The first malicious commit reached tensorlakeai/tensorlake's main branch at 01:20 UTC under a maintainer's identity. The attacker pushed directly to the repository without using a pull request.
Sonatype Research Labs identified a fallback capable of creating a public GitHub repository and uploading collected data under results/, including a stolen GitHub token in the data and commit message under specific conditions. The report did not confirm successful publication of stolen data, repository modification, or downstream compromise.
Tensorlake withdrew the compromised npm SDK release, version 0.5.144, and updated the SDK to version 0.5.145.
OX Security reported that five GitHub repositories containing stolen credentials had been uploaded following the Tensorlake attack. Researchers also identified previously unseen encryption keys, suggesting possible reuse by another operator but not confirming attribution.
The compromised tensorlake@0.5.144 release was reported as no longer available for download from the npm registry. Users who installed it were advised to remove it immediately and rotate their credentials.
GMO Flatt researchers reported Windows persistence through an ONLOGON scheduled task and enumeration of AWS SSM Parameter Store and Secrets Manager across all regions. They also published artifact hashes and network indicators, while cautioning that the investigation remained preliminary.
StepSecurity and Aikido disclosed install-time credential theft, npm and GitHub propagation, editor-based persistence, browser-data collection, and blockchain-based command-and-control resolution. StepSecurity identified a gh-token-monitor service that deletes the user's home directory if GitHub rejects the monitored token, warning users to remove it before revoking credentials.
StepSecurity's AI Package Analyst detected tensorlake@0.5.144, and StepSecurity reported the compromise to maintainers through GitHub issue #1014.
An Ethereum transaction dated September 21 contained iseekaigogo[.]com in its input data. Aikido identified it as the latest transaction used by the malware's blockchain-based command-and-control lookup; the transaction's year was not stated.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 13 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
14 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcesonatype.com
Open sourcethecybersecguru.com
Open sourcetheregister.com
Open sourcesocket.dev
Open sourceflatt.tech
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.