Valid Provenance, Poisoned Source: TensorLake 0.5.144 Shipped the Shai-Hulud Worm
On 8 October 2026 at 01:12:07 UTC, the npm package tensorlake — the official TypeScript SDK for TensorLake's agent-sandbox infrastructure, running at roughly 12,000 weekly downloads — published version 0.5.144. At 01:23:10 UTC, eleven minutes later, Socket flagged it: the release carried a preinstall hook running node lib/setup.mjs and an obfuscated worm payload from the Shai-Hulud family. No import was needed. No agent had to run. Where lifecycle scripts are permitted, npm install alone executes the loader, which invokes the payload — and the SDK teams install to create isolated sandboxes became the infection itself.
TensorLake's product is isolated sandboxes for running untrusted, LLM-generated code, with checkpointing, suspend and resume. The compromise inverts that promise precisely: the exposure lands on the developer workstation, application server or build runner before any generated code reaches a sandbox, and install-time code inherits the permissions of the installing process — deployment credentials and all.
Provenance attested the run, not the source
Endor Labs' analysis carries the finding defenders should sit with. The poisoned release shipped through the project's normal GitHub Actions pipeline and carried valid build provenance. Provenance confirms where a build came from, not that the source was clean: the attacker modified the project's main branch first, then let the trusted pipeline publish the result. The most likely root cause is a compromised maintainer account — textbook Shai-Hulud behaviour, and the same shape we documented in the SubQL @5.8.3 build-to-publish substitution, where the attested artifact faithfully recorded a hostile build. Any policy that treats “has valid provenance” as “is safe to install” fails open against exactly this attack.
The payload pair matches the August ChainDrop structure file for file: a small obfuscated loader (lib/setup.mjs) and a large obfuscated payload (lib/Math_Symbol.js, about 856 KB), internally tagged with the marker WORMTAG. The loader checks for CI environments before running, and the worm's propagation path is credential-driven — it enumerates packages under the victim's publishing identity, builds Sigstore provenance for them, and republishes compromised versions, with strings referencing a fake Copilot/Dependabot workflow suggesting planted GitHub Actions jobs on top.
It eats agent-developer credentials first
Socket's assessment reads like a census of everything on a modern AI developer's machine. Collection targets include npm tokens (.npmrc, the token API, OIDC exchange), GitHub tokens checked for repository and workflow permissions, AWS credentials via IMDS/ECS/Secrets Manager/SSM, HashiCorp Vault at 127.0.0.1:8200, Kubernetes service-account tokens and kubeconfigs, SSH keys, .env files, wallets — and explicitly configuration and MCP files for .claude, .cursor, .kiro, Windsurf and Zed. The worm is aimed at the intersection of supply-chain access and agent tooling: steal the publisher's keys to spread through npm, and sweep up the agent configs to widen whatever comes next. Persistence plus remote-code execution means removing the dependency does not remove the attacker.
Two infrastructure details show operational maturity. The payload carries no hardcoded command-and-control domain: it resolves its endpoint through an Ethereum smart contract queried across roughly 30 public RPC endpoints, with a GitHub fallback — the same resolver design reported in the August keyv compromise. And the “hostage token” component is a PowerShell monitor persisted as an ONLOGON scheduled task that polls api.github.com/user with the stolen GitHub token; when the token is revoked, it fires an attacker-supplied handler through Invoke-Expression. The code carries the calling card seen in earlier waves: revocation triggers retaliation, up to wiping the owner's machine. Rotating a stolen token — the first instinct — is the tripwire.
ChainDrop keeps scaling
This is the same campaign lineage as the August ChainDrop compromises of keyv, cacheable and related packages, which Palo Alto Networks Unit 42 traced to the Shai-Hulub family at over 400 infected packages. TensorLake moves that pattern into tooling used to build and operate AI agents — after Mandiant's hijacked-coding-assistant findings and the TeamPCP retrospective on agents living off the land, the worm family's interest in developer AI tooling is no longer a hypothesis. Combined with GhostAction's un-cleaned workflow implants, the week's theme is uncomfortable: trusted developer pipelines keep publishing attacker code, and the implants keep surviving cleanup.
What to do
- Search manifests, lockfiles, build logs and deployed artifacts for
tensorlake@0.5.144and block the version. The sixtensorlake-native-*@0.5.144platform packages came from the same run — no payload found in them, but avoid the whole release line. 0.5.143and earlier are clean. The bad version has been removed from npm, which stops new installs and does nothing for machines that already ran the hook.- Treat every host that ran the install scripts as compromised, not merely dirty: isolate, investigate persistence (including the ONLOGON task on Windows), and rotate every credential reachable from that host — npm, GitHub, AWS, Vault, Kubernetes — with the revocation tripwire in mind. Plan the rotation so the dead-man switch fires nowhere important.
- Stop treating provenance as a cleanliness signal. Pin versions, diff published tarballs against source, and block lifecycle scripts where your toolchain allows it. Provenance tells you the pipeline ran; it cannot tell you the branch was yours.
Verification note: the publication timestamp (01:12:07 UTC), Socket's flag time (01:23:10 UTC), the preinstall hook, the Bun-launched loader and Math_Symbol.js payload names, the ~12,000 weekly download figure, the credential-target list, the Ethereum-contract resolver with ~30 RPC endpoints and GitHub fallback, and the hostage-token ONLOGON/Invoke-Expression mechanism were read directly from Socket's 8 October write-up. The valid-provenance-via-trusted-pipeline finding, the main-branch modification, the likely compromised maintainer account, the 856 KB payload size, the internal WORMTAG marker, the CI check, the six native packages' status and the 0.5.143-clean statement were read directly from Endor Labs' analysis. The 12,000 figure describes overall package usage, not downloads of the malicious version or confirmed infections — Socket's own caveat, repeated here because it will be misquoted elsewhere. The August ChainDrop scope (400+ packages, keyv/cacheable-request) is Palo Alto Networks Unit 42's reporting as surfaced in secondary coverage; we have not independently analysed any payload.
Sources:
- Socket — TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack (8 October 2026)
- Endor Labs — Tensorlake npm package compromised by Shai-Hulud in latest software supply chain attack (8 October 2026)
- Palo Alto Networks Unit 42 — Evolution of Web3 in Cloud Supply Chain Attacks (ChainDrop/Shai-Hulud background)