Threats & Adversaries · Supply Chain

Tensorlake npm release carried a self-spreading worm

Socket said tensorlake npm version 0.5.144 was compromised with a Bun-based Shai-Hulud worm that steals credentials and can republish infected packages. The package has since been removed from the registry.

The malicious release runs from a preinstall hook, so the code fires during install before a developer can inspect the package. From there it can pull secrets from files, CI systems, Kubernetes, Vault, GitHub, and other local sources, keep persistence on the host, and use stolen publishing identity to spread onward through new package uploads.

For teams that install npm packages inside build systems, the exposure is bigger than one tainted dependency: any trusted secret reachable by the install process may already be gone, and republishing under the victim’s identity can widen the incident into the supply chain.

2 sources · 5h ago

Timeline

Sources

Part of the PlainSec briefing for 2026-10-08

Every edition of this story: Tensorlake npm release carried a self-spreading worm

More from today