Compromised Tensorlake npm package spreads Shai-Hulud worm that steals developer credentials and republishes itself
Socket and StepSecurity reported that version 0.5.144 of the tensorlake npm package, a TypeScript SDK, was published with obfuscated malware tied to the Shai-Hulud supply chain attack. A preinstall hook launches a loader that runs a worm under the Bun runtime. It harvests npm, GitHub, AWS, Vault, Kubernetes, and SSH credentials, .env files, cryptocurrency wallets, and configuration for Claude, Cursor, and other tools, then enumerates the victim's other packages and republishes them with forged provenance to spread. A PowerShell monitor watches the stolen GitHub token and runs a destructive handler if the victim revokes it, so remove the package before rotating that token.
- Check
- Check whether any project installed tensorlake 0.5.144, remove it before revoking tokens to avoid the destructive handler, then rotate all exposed credentials and audit republished packages.
- Affected
- Developers who installed the compromised tensorlake version had npm, GitHub, cloud, and SSH credentials stolen, and the worm may have republished their own packages with forged provenance.
- Fix
- Remove the malicious package, rotate npm, GitHub, cloud, and SSH credentials, review published packages and GitHub Actions workflows for tampering, and follow Socket and StepSecurity guidance on token revocation order.