Back to News
RSS feedwww.theregister.com

Shai-Hulud Worm Hits Tensorlake AI SDK in npm Supply-Chain Attack

Summary

The credential-stealing Shai-Hulud worm was found in version 0.5.144 of Tensorlake’s npm SDK, which is used to create and manage environments for the company’s cloud-native platform for isolated AI agents and untrusted AI-authored code. The package had about 12,000 downloads per week and its repository had more than 1,000 stars, so researchers warned that the compromise could affect a substantial user base. Analysis linked the release to the ChainDrop variant previously used against the keyv and flat-cache npm dependencies. The malware can exfiltrate crypto-wallet data, browser passwords, GitHub Actions secrets, cloud credentials, service-account tokens, and other credentials, while maintaining a command-and-control connection for further instructions. Under specific conditions, monitoring of stolen GitHub tokens can also trigger deletion of an infected user’s home directory when a token is revoked. Socket warned that the SDK installation script runs on the developer machine, application server, or build runner outside Tensorlake’s sandbox, allowing the installing process’s permissions and secrets to be exposed before AI-generated code runs. The infected version was published and removed on the same day after Socket flagged it 11 minutes after publication. Tensorlake pulled the package and issued version 0.5.145. Security researchers recommended checking whether version 0.5.144 was installed, disabling the malicious token monitor before revoking affected credentials, and rebuilding compromised systems from a trusted source before restoring secrets.