Tensorlake npm SDK 0.5.144 ships credential-stealing Shai-Hulud worm, removed within a day
Security firms Socket and StepSecurity report that version 0.5.144 of the Tensorlake npm package, a TypeScript SDK for AI agent sandboxes, was compromised to deliver the Shai-Hulud worm. The malware, according to Socket, harvests npm, GitHub and AWS tokens, SSH keys and cryptocurrency wallet data, and can spread by republishing packages under the victim's publishing identity. SafeDep says npm removed the version after about eight minutes of automated flagging, and the maintainers released 0.5.145.
Bottom line — Socket and SafeDep both advise treating every secret on any system that installed 0.5.144 as exposed, and rotating them carefully.
Go deeper 7
-
Socket says the package receives about 12K weekly downloads, while Cyber Security News cites over 100,000 lifetime installs; both describe overall usage, not confirmed infections.
-
SafeDep reports the attacker used a repository administrator account to commit the payload through the GitHub web interface, bypassing the need for an npm token.
-
Socket describes a 'hostage token' component that polls the stolen GitHub token and runs destructive deletion if the token is revoked, so SafeDep and Daily Security Review both warn that revocation order matters.
-
Cyber Security News, citing Aikido, reports the malware targets 14 cryptocurrency wallet extensions, including MetaMask and Phantom.
-
Daily Security Review says the malicious commit landed early on 7 October and the release followed on 8 October, while SafeDep says the release was recorded at 01:12 UTC on 8 October.
-
Socket says the payload resolves its command-and-control endpoint through an Ethereum contract with a GitHub fallback; SafeDep and Cyber Security News name the domain iseekaigogo[.]com.
-
Security Arsenal, a vendor blog, publishes Sigma, KQL and Velociraptor detection rules and a remediation script for the incident.