Full Report
The npm package known as "tensorlake," a TypeScript software development kit (SDK) for Tensorlake applications, sandboxes, and cloud services, was compromised as part of a ChainDrop / Shai-Hulud supply chain attack. The malicious version 0.5.144 "contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code," Socket said
Analysis Summary
# Tool/Technique: Shai-Hulud / ChainDrop (via compromised Tensorlake SDK)
## Overview
Shai-Hulud is a sophisticated, self-propagating credential-stealing worm designed to compromise software supply chains. In this specific instance, it targeted the `tensorlake` npm package (a TypeScript SDK for AI applications). The malware automates the theft of high-value secrets, establishes persistence across developer environments, and utilizes a "hostage token" mechanism to execute destructive code if the victim attempts to revoke stolen credentials.
## Technical Details
- **Type:** Malware (Worm / Infostealer / Remote Access Trojan)
- **Platform:** Cross-platform (Node.js/Bun runtime, Windows/PowerShell, Linux/Kubernetes, CI/CD environments)
- **Capabilities:** Credential harvesting, self-propagation, remote code execution (RCE), persistence, and hostage-token monitoring.
- **First Seen:** Early variants documented August 2026; Tensorlake compromise occurred October 7, 2026.
## MITRE ATT&CK Mapping
- **[TA0001 - Initial Access]**
- [T1195.002 - Supply Chain Compromise: Compromise Software Dependencies]
- **[TA0003 - Persistence]**
- [T1574.006 - Hijack Execution Flow: LD_PRELOAD / Preinstall Hooks]
- [T1053.007 - Scheduled Task/Job: Tasks.json (VS Code)]
- **[TA0006 - Credential Access]**
- [T1555 - Credentials from Password Stores]
- [T1552.001 - Unsecured Credentials: Private Keys]
- **[TA0007 - Discovery]**
- [T1083 - File and Directory Discovery]
- **[TA0011 - Command and Control]**
- [T1584.005 - Compromise Infrastructure: Botnet Control Server (Ethereum Contract)]
- [T1102.001 - Web Service: Dead Drop Resolver (GitHub Public Repo)]
- **[TA0010 - Exfiltration]**
- [T1567 - Exfiltration Over Web Service]
## Functionality
### Core Capabilities
- **Multi-Source Stealer:** Harvests credentials from CI environments, Kubernetes configs, HashiCorp Vault, AWS, SSH keys, `.env` files, and crypto wallets.
- **Supply Chain Worm:** Enumerates the victim's npm publishing identity, builds Sigstore provenance, and automatically republishes compromised versions of the victim's own packages to infect others.
- **Browser Data Extraction:** Drops the `HackBrowserData` binary to exfiltrate stored passwords and cookies.
- **IDE/AI Tool Persistence:** Modifies `.vscode/tasks.json` and `.claude/settings.json` to trigger execution when the developer opens the project in VS Code or Claude Code.
### Advanced Features
- **Hostage Token Mechanism:** A PowerShell monitor polls `api.github.com` using stolen tokens. If the token is revoked (HTTP 401), it triggers an `Invoke-Expression` handler to execute a destructive routine.
- **Blockchain C2 Resolution:** Uses an Ethereum contract to resolve the active C2 domain.
- **Dead Drop Resolver:** Utilizes GitHub repositories with specific descriptions ("Shai-Hulud: Here We Go Again") as a fallback for staging encrypted data.
## Indicators of Compromise
- **File Names:**
- `package/lib/setup.mjs` (Loader)
- `package/lib/Math_Symbol.js` (Main payload)
- `.claude/settings.json`
- `.vscode/tasks.json`
- **Network Indicators:**
- `iseekaigogo[.]com` (C2)
- `api.github[.]com/user` (Token monitoring)
- **Behavioral Indicators:**
- `npm publish` events triggered by automated CI/CD workflows unexpectedly.
- Unexpected `Invoke-Expression` (IEX) calls in PowerShell.
- Automated creation of Sigstore provenance for unauthorized package versions.
## Associated Threat Actors
- **ChainDrop / Shai-Hulud Operators:** Known for large-scale npm and Open VSX repository poisoning campaigns.
## Detection Methods
- **Signature-based:** Scanning for `HackBrowserData` binaries and specific obfuscation patterns in `Math_Symbol.js`.
- **Behavioral:**
- Monitoring for unauthorized modifications to `.vscode` or `.env` files within developer repositories.
- Auditing npm registry tokens for unusual publishing patterns.
- Detecting repeated polling of GitHub API from developer workstations.
- **YARA:** Target strings related to "Shai-Hulud: Here We Go Again" and Sigstore provenance manipulation.
## Mitigation Strategies
- **Dependency Pinning:** Use `package-lock.json` and avoid automated updates to new, unvetted versions.
- **Secret Management:** Use short-lived credentials (OIDC) for CI/CD instead of long-lived npm/GitHub tokens.
- **Network Segmentation:** Restrict developer workstations from reaching unknown C2 domains and monitor for excessive API calls to GitHub/AWS from local scripts.
- **Code Signing:** Verify Sigstore provenance but remain cautious, as this malware attempts to forge it.
## Related Tools/Techniques
- **HackBrowserData:** Open-source tool used for credential extraction.
- **Mini Shai-Hulud:** A lighter variant used in previous npm poisoning campaigns (e.g., Keyv, Cacheable).
- **Bun Runtime:** Used by the malware to execute JavaScript payloads outside of standard Node.js environments.