The images in this article were generated with artificial intelligence. How we publish
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family known as ChainDrop / Shai-Hulud. The malicious version identified - 0.5.144 - was removed from the npm record after independent analysis tracked in its content a pre-installation hook and multiple artifacts intended to steal credentials, exfilter secrets, maintain persistence and run remote code.
The components investigated show that, during the installation, the package was running a preinstall hole which invoked the package / lib / setup.mjs. file That boot loaded an ofuscado "loader" that ran, on the runtime Bun, the main payload (package / lib / Math _ Symbol.js). The documented technical behavior includes collection of credentials from local files and CI environments, extraction from Kubernetes and HashiCorp Vault, installation of the HackBrowserData binary to steal browser data, exfiltration of encrypted information and persistence mechanisms that allow the attacker to keep access even if the dependence is removed.

Among the types of secrets confirmed as target by the analyses are npm and GitHub tokens, AWS credentials and secrets, Vault tokens and credentials, Kubernetes credentials, SSH keys, .env files, cryptomoneda portfolios and messaging application data. References to configuration files associated with IA agents and assistant services - for example, Claude-related files and other platforms - were also identified, suggesting that the actor was looking for useful information to exploit IA infrastructure or automation agents.
The detected propagation vector combines two dangerous capabilities: on the one hand, the worm lists packages associated with the identity of the victim's publicator, generates a provenance test (Sigstore provenance) and republishes committed versions to infect other victims; on the other, it plants GitHub's false actions workflows (chains similar to Copilot / Dependabot) and writes files such as .claude / settings.json and .vscode / tasks.json in repos that it can reach, so that the malicious load is reactivated in a project. The use of an Etheum contract to resolve a command and control endpoint (C2) and the use of public repositories in GitHub as a fallback mechanism to accommodate stolen data were also documented.
Confirmed facts: version 0.5.144 of the package was published and then removed from the npm record; the package contained a pre-install hook that activated opussed files and a payload based on Bun; malware sought and exfiltered a wide range of secrets, leaving known binaries (HackBrowserData) and planted artifacts in repositories; there were malicious commits to the tensorlakeai / tensorlake repository and the first modification reported was on October 7, 2026, according to analysis published by third parties. These findings come from technical reports published by response teams that analyzed the release and the artifacts in the repository.
Incognites and estimates: the exact scale of infection (number of affected facilities or organizations involved) has not been published in a comprehensive manner; nor is the scope of credentials actually exploited or if the attacker succeeded in compromising high-impact accounts in specific companies publicly confirmed. The use of the "hostel token" monitor that runs code with Invoke-Expression when a token is revoked has been observed in previous waves and is considered a high-risk tactic; however, the actual destructive impact of that routine on this campaign, if it was executed, remains subject to forensic investigation in affected hosts.
Who does this affect? Mainly to developers and organizations that have installed version 0.5.144 of the tensorlake package - directly or transitively - in development environments, CI / CD, containers or base images. The vector is especially critical in automated pipelines and environments with secrets mounted in the execution context (e.g., CI runners with tokens with permissions, containers with cloud credentials or IA agents with stored keys). Also at risk are those who publish npm packages with the same maintainer identity, because the worm tries to reuse these credentials to spread malicious versions.
Practical consequences: exposure of a CI token or AWS key can result in data exfiltration, unauthorized deployments, fraudulent cloud spending, usurpation of repository accounts and side pivoting within corporate networks. The persistence at the level of repository and workflows means that the mere elimination of the dependence does not guarantee the eradication of the actor if the actor has left artifacts in the code or skewed the distribution chain of packages.
Concrete and immediate measures that should be taken by those who have installed the compromised version: first, identify if their environment contains version 0.5.144 by reviewing package.json, package-lock.json, yarn.lock, pnpm.-lock.yaml and running inspection commands on projects and build servers (e.g., npm ls tensorlake or grep using lock files). If the malicious version appears, remove it immediately and isolate hosts where the unit was installed.
Second, rotate all potentially exposed credentials: revoke and reissue npm and GitHub tokens, AWS keys and roles, Vault credentials, Kubernetes service accounts and any SSH key that may have resided in those environments. Do not just rotate them once: each secret that may have been accessible to the infected process should be considered compromised and replaced.
Third, to conduct forensic searches: to search for files and processes that match package / lib / setup.mjs or package / lib / Math _ Symbol.js, to detect HackBrowserData binaries, to review cron, services and programmed tasks, and to audit repositories and GitHub Actions in search of unauthorized workflows or suspicious commitments (including .claude / settings.json and .vscode / tasks.json files). Isolate and preserve evidence before cleaning to allow further investigation.

Fourth, hygienize images and runners: rebuild containers and images from trusted origins, not reuse binary artifacts that have been in compromised environments and regenerate credentials associated with runners and agents. In pipelines, avoid mounting secrets in flat text in containers and prefer temporary and rotary mechanisms (e.g. short-term credentials or OIDC mechanisms where possible).
Finally, at the organizational level, run unit scanning through the fleet of repositories and machines, activate detection of outgoing anomalous behavior (connections to suspicious domains such as iseekaigogo [.] com), and strengthen package publication controls (human reviews in releases, restriction of publication permits and use of verifiable artifacts signatures). To better understand the guarantees of provenance and mitigation of abuse in signatures, see Sigstore documentation: https: / / sigstore.dev. To check the existence and status of the package concerned and its history in the register, see the npm page: https: / / www.npmjs.com / package / tensorlake and the associated repository in GitHub: https: / / github.com / tensorlakeai / tensorlake.
This intrusion is a new iteration of the trend observed since August 2026 by which actors attack the JavaScript supply chain and now extend the focus to IA infrastructure and automated agents. The operational lesson is clear: the simple presence of a unit in node _ modules can be a vector of commitment when that unit runs code in installation hooks or in pipelines with extensive permissions. Review publishing policies, minimize privileges in CI tokens and set up secret detection in repositories are measures that significantly reduce the risk that a similar incident will scale within an organization.
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...

LibreOffice / OpenOffice Calc allows remote source execution when opening ODB / JDBC leaves
Researchers have shown that a malicious spreadsheet can force LibreOffice and Apache OpenOffice to run code controlled by an attacker at the time the file is opened, without sho...

Denmark confirms unauthorized access to the RCP that affected 8.8 million records
The Danish government confirmed that for about ten days in September there were unauthorized access to the Central Peru Register (CPR) the national population database. Accordin...