The npm package 'tensorlake', a TypeScript SDK for Tensorlake applications and services, suffered a significant security breach as part of a chain supply attack known as ChainDrop or Shai-Hulud. The compromised version, 0.5.144, was found to contain obfuscated malware designed to steal credentials, exfiltrate secrets, establish persistence, and execute remotely supplied code. This version has been removed from the npm registry.
The analysis of the malicious release reveals a preinstall hook that launches a JavaScript file, which in turn triggers a credential-stealing worm. This worm targets local files, CI environments, Kubernetes, and Vault sources to harvest sensitive information. Additionally, it drops a binary to exfiltrate the collected data and maintains persistence, allowing attackers continued access even after the malicious dependency is removed.
The malware exploits an Ethereum contract to find its command-and-control endpoint, with GitHub serving as a backup to store encrypted stolen data. It also involves a 'hostage token' component that monitors GitHub tokens and can execute destructive commands if the token is revoked by the victim.
The malicious files were introduced into the main branch of the 'tensorlakeai/tensorlake' repository by a maintainer, with the rogue commit occurring on October 7, 2026. This attack follows a pattern seen in earlier ChainDrop incidents, which targeted numerous npm packages with similar threats. The incident underscores the vulnerabilities in AI infrastructure and the need for robust security measures. Users who installed the affected version should remove it immediately and update their credentials.

