StepSecurity said the first rogue commit reached tensorlakeai/tensorlake on October 7, 2026, under a maintainer’s name. The npm release that followed carries a worm that harvests credentials.
At a Glance
- Tensorlake’s npm package, version 0.5.144, contains obfuscated malware that harvests credentials and executes remotely supplied code.
- The worm enumerates packages tied to a victim’s publishing identity and republishes compromised versions.
- Stolen data includes npm tokens, GitHub tokens, AWS credentials, Vault and Kubernetes credentials, SSH keys, and environment files (.env).
- Version 0.5.144 is no longer available for download from the npm package registry. Anyone who installed it is advised to remove it immediately and rotate their credentials.
The release came from the project’s own pipeline
The malicious files landed on the main branch of tensorlakeai/tensorlake, StepSecurity said, and the package was released from that same repository. The first rogue commit came at 01:20 a.m. UTC. A day later, the repository’s release workflow published the package to npm.
The reported wording says only that the files were pushed under a maintainer’s name. No source here ties the push to the maintainer.
Analysis of the compromised release shows a preinstall hook designed to launch a JavaScript file. That file is an obfuscated loader that starts the main credential-stealing and self-propagating worm using the Bun runtime.
🚨 npm package tensorlake@0.5.144 is compromised. It steals credentials and spreads using your npm and GitHub tokens. Revoke the stolen GitHub token and it wipes your home directory. Pin to 0.5.143. Read this first: https://t.co/HnsZaPEq1B
— StepSecurity (@step_security) October 8, 2026
The worm reaches outward too. Socket said it builds Sigstore provenance for the versions it republishes. It also contains strings referencing a fake Copilot/Dependabot workflow. Socket said those suggest it plants GitHub Actions workflows.
For command and control, the malware uses an Ethereum contract to resolve its endpoint, iseekaigogo[.]com. GitHub is the fallback: encrypted stolen data is staged in a public repository described as “Shai-Hulud: Here We Go Again.“
Revoking a stolen GitHub token may set off a trap
A “hostage token” component uses a PowerShell monitor to repeatedly poll api.github.com/user with the stolen GitHub token. If the victim revokes the token, the monitor runs an attacker supplied handler through the Invoke-Expression cmdlet. The PowerShell code is designed to likely trigger a destructive routine, a tactic observed in earlier Shai-Hulud waves.
A cautious order helps reduce risk: isolate the machine and look for the monitor before revoking the GitHub token. This is a general precaution, not researcher guidance.
Then rotate every secret the machine could reach, including npm, GitHub, AWS, Vault, Kubernetes, SSH and environment-file (.env) values. Review GitHub Actions workflows for entries you did not write.
Whats Next?
StepSecurity’s Ashish Kurmi said the malware drops two files into repos it can reach. One is a Claude settings file (.claude/settings.json). The other is a VS Code tasks file (.vscode/tasks.json). He said it runs again when someone opens the project in Claude Code or VS Code.
Removing the package therefore ends only part of the exposure.
































































