Full Report
Credential-stealing malware detected within minutes of npm release, but impact remains unknown
Analysis Summary
# Incident Report: Shai-Hulud Worm Compromise of Tensorlake SDK
## Executive Summary
A credential-stealing worm, identified as a variant of Shai-Hulud (ChainDrop), successfully compromised the npm package for Tensorlake’s SDK (version 0.5.144). The malware was designed to exfiltrate a wide array of credentials and secrets while maintaining a destructive persistence mechanism that monitors token revocation. Although the malicious package was flagged and removed within 11 minutes, its high download volume (approx. 12,000/week) poses a significant risk to AI infrastructure developers.
## Incident Details
- **Discovery Date:** Thursday, October 8, 2026
- **Incident Date:** October 8, 2026
- **Affected Organization:** Tensorlake (AI Agent Platform)
- **Sector:** Technology / Artificial Intelligence / Software Development
- **Geography:** Global (npm distribution)
## Timeline of Events
### Initial Access
- **Date/Time:** October 8, 2026 (Morning UTC)
- **Vector:** Supply Chain Attack / Repository Compromise
- **Details:** Attackers published a malicious version (0.5.144) of the `tensorlake` npm package. The installation script was designed to execute automatically upon package download/install.
### Lateral Movement
- **Details:** The worm is designed for self-propagation by seeking out developer credentials (such as GitHub tokens) to compromise additional repositories and npm dependencies.
### Data Exfiltration/Impact
- **Details:** The malware targeted crypto wallets, browser passwords, GitHub Actions secrets, cloud credentials, and service-account tokens. It maintained an active link to Command and Control (C2) infrastructure for further instruction.
### Detection & Response
- **Discovery:** Detected by Socket’s security engine 11 minutes after publication.
- **Response actions taken:** npm removed the malicious version; Tensorlake pulled the package from their repository and released version 0.5.145 as a clean update.
## Attack Methodology
- **Initial Access:** Supply chain injection via a popular npm package.
- **Persistence:** Maintains an open line to C2 infrastructure; monitors stolen GitHub tokens for revocation.
- **Privilege Escalation:** Inherits permissions of the installing process (Developer/Build Server level).
- **Defense Evasion:** Executes outside of Tensorlake’s intended AI sandboxes by running during the SDK installation phase.
- **Credential Access:** Scraping browser data, searching for `.env` files, and accessing system keychains.
- **Discovery:** Reconnaissance of the local file system for secrets and configuration files.
- **Lateral Movement:** Self-propagation via stolen GitHub and npm tokens.
- **Collection:** Aggregation of cloud, GitHub, and wallet credentials.
- **Exfiltration:** Data sent to attacker-controlled C2 servers.
- **Impact:** Potential destruction of the user's home directory (`/home` or `~`) if stolen tokens are revoked while the malware is active.
## Impact Assessment
- **Financial:** Unknown; potential theft of cryptocurrency assets via wallet credentials.
- **Data Breach:** High risk of leaked GitHub Actions secrets and cloud provider (AWS/GCP/Azure) credentials.
- **Operational:** High risk; the destructive "nuke" feature targeting home directories could cause total loss of local developer data.
- **Reputational:** Moderate; Tensorlake acted quickly, but the incident highlights vulnerabilities in AI infrastructure supply chains.
## Indicators of Compromise
- **File indicators:** `tensorlake` npm package version `0.5.144`.
- **Behavioral indicators:** Unexplained network traffic to unknown C2 IPs; automated deletion of files following token revocation; `postinstall` scripts running unexpected shell commands.
## Response Actions
- **Containment:** Version 0.5.144 was delisted from npm and the Tensorlake GitHub repository.
- **Eradication:** Developers are advised to rebuild compromised systems from trusted sources rather than simply deleting the package.
- **Recovery:** Release of version 0.5.145; recommendation to disable the malicious token monitor *before* revoking credentials to avoid the destructive payload.
## Lessons Learned
- **Key takeaways:** AI sandboxing is ineffective if the SDK used to manage the sandbox is itself compromised. Malware is becoming increasingly "spiteful," adding destructive payloads to punish incident responders.
- **What could have been done better:** Enhanced MFA/branch protection on the npm publishing workflow might have prevented the unauthorized release.
## Recommendations
- **Prevention:** Implement automated dependency scanning (e.g., Socket, Snyk) that flags new package versions for suspicious install scripts.
- **Process:** Use "lockfiles" (`package-lock.json`) and vet updates before moving to the latest version of popular SDKs.
- **Hardening:** Use short-lived, scoped tokens for CI/CD processes rather than long-lived personal access tokens.