Threats · 4h ago
Socket said tensorlake npm version 0.5.144 was compromised with a Bun-based Shai-Hulud worm that steals credentials and can republish infected packages. The package has since been removed from the registry.
The malicious release runs from a preinstall hook, so the code fires during install before a developer can inspect the package. From there it can pull secrets from files, CI systems, Kubernetes, Vault, GitHub, and other local sources, keep persistence on the host, and use stolen publishing identity to spread onward through new package uploads.
For teams that install npm packages inside build systems, the exposure is bigger than one tainted dependency: any trusted secret reachable by the install process may already be gone, and republishing under the victim’s identity can widen the incident into the supply chain.
2 sources covering this story
Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm
Malicious tensorlake npm version 0.5.144 contained a Shai-Hulud worm that harvests credentials and can republish compromised packages.
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
Part of the PlainSec briefing for 2026-10-08