ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal

Author: Published 6 min de lectura 1 reading

The images in this article were generated with artificial intelligence. How we publish

A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family known as ChainDrop / Shai-Hulud. The malicious version identified - 0.5.144 - was removed from the npm record after independent analysis tracked in its content a pre-installation hook and multiple artifacts intended to steal credentials, exfilter secrets, maintain persistence and run remote code.

The components investigated show that, during the installation, the package was running a preinstall hole which invoked the package / lib / setup.mjs. file That boot loaded an ofuscado "loader" that ran, on the runtime Bun, the main payload (package / lib / Math _ Symbol.js). The documented technical behavior includes collection of credentials from local files and CI environments, extraction from Kubernetes and HashiCorp Vault, installation of the HackBrowserData binary to steal browser data, exfiltration of encrypted information and persistence mechanisms that allow the attacker to keep access even if the dependence is removed.

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
Image generated with IA.

Among the types of secrets confirmed as target by the analyses are npm and GitHub tokens, AWS credentials and secrets, Vault tokens and credentials, Kubernetes credentials, SSH keys, .env files, cryptomoneda portfolios and messaging application data. References to configuration files associated with IA agents and assistant services - for example, Claude-related files and other platforms - were also identified, suggesting that the actor was looking for useful information to exploit IA infrastructure or automation agents.

The detected propagation vector combines two dangerous capabilities: on the one hand, the worm lists packages associated with the identity of the victim's publicator, generates a provenance test (Sigstore provenance) and republishes committed versions to infect other victims; on the other, it plants GitHub's false actions workflows (chains similar to Copilot / Dependabot) and writes files such as .claude / settings.json and .vscode / tasks.json in repos that it can reach, so that the malicious load is reactivated in a project. The use of an Etheum contract to resolve a command and control endpoint (C2) and the use of public repositories in GitHub as a fallback mechanism to accommodate stolen data were also documented.

Confirmed facts: version 0.5.144 of the package was published and then removed from the npm record; the package contained a pre-install hook that activated opussed files and a payload based on Bun; malware sought and exfiltered a wide range of secrets, leaving known binaries (HackBrowserData) and planted artifacts in repositories; there were malicious commits to the tensorlakeai / tensorlake repository and the first modification reported was on October 7, 2026, according to analysis published by third parties. These findings come from technical reports published by response teams that analyzed the release and the artifacts in the repository.

Incognites and estimates: the exact scale of infection (number of affected facilities or organizations involved) has not been published in a comprehensive manner; nor is the scope of credentials actually exploited or if the attacker succeeded in compromising high-impact accounts in specific companies publicly confirmed. The use of the "hostel token" monitor that runs code with Invoke-Expression when a token is revoked has been observed in previous waves and is considered a high-risk tactic; however, the actual destructive impact of that routine on this campaign, if it was executed, remains subject to forensic investigation in affected hosts.

Who does this affect? Mainly to developers and organizations that have installed version 0.5.144 of the tensorlake package - directly or transitively - in development environments, CI / CD, containers or base images. The vector is especially critical in automated pipelines and environments with secrets mounted in the execution context (e.g., CI runners with tokens with permissions, containers with cloud credentials or IA agents with stored keys). Also at risk are those who publish npm packages with the same maintainer identity, because the worm tries to reuse these credentials to spread malicious versions.

Practical consequences: exposure of a CI token or AWS key can result in data exfiltration, unauthorized deployments, fraudulent cloud spending, usurpation of repository accounts and side pivoting within corporate networks. The persistence at the level of repository and workflows means that the mere elimination of the dependence does not guarantee the eradication of the actor if the actor has left artifacts in the code or skewed the distribution chain of packages.

Concrete and immediate measures that should be taken by those who have installed the compromised version: first, identify if their environment contains version 0.5.144 by reviewing package.json, package-lock.json, yarn.lock, pnpm.-lock.yaml and running inspection commands on projects and build servers (e.g., npm ls tensorlake or grep using lock files). If the malicious version appears, remove it immediately and isolate hosts where the unit was installed.

Second, rotate all potentially exposed credentials: revoke and reissue npm and GitHub tokens, AWS keys and roles, Vault credentials, Kubernetes service accounts and any SSH key that may have resided in those environments. Do not just rotate them once: each secret that may have been accessible to the infected process should be considered compromised and replaced.

Third, to conduct forensic searches: to search for files and processes that match package / lib / setup.mjs or package / lib / Math _ Symbol.js, to detect HackBrowserData binaries, to review cron, services and programmed tasks, and to audit repositories and GitHub Actions in search of unauthorized workflows or suspicious commitments (including .claude / settings.json and .vscode / tasks.json files). Isolate and preserve evidence before cleaning to allow further investigation.

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
Image generated with IA.

Fourth, hygienize images and runners: rebuild containers and images from trusted origins, not reuse binary artifacts that have been in compromised environments and regenerate credentials associated with runners and agents. In pipelines, avoid mounting secrets in flat text in containers and prefer temporary and rotary mechanisms (e.g. short-term credentials or OIDC mechanisms where possible).

Finally, at the organizational level, run unit scanning through the fleet of repositories and machines, activate detection of outgoing anomalous behavior (connections to suspicious domains such as iseekaigogo [.] com), and strengthen package publication controls (human reviews in releases, restriction of publication permits and use of verifiable artifacts signatures). To better understand the guarantees of provenance and mitigation of abuse in signatures, see Sigstore documentation: https: / / sigstore.dev. To check the existence and status of the package concerned and its history in the register, see the npm page: https: / / www.npmjs.com / package / tensorlake and the associated repository in GitHub: https: / / github.com / tensorlakeai / tensorlake.

This intrusion is a new iteration of the trend observed since August 2026 by which actors attack the JavaScript supply chain and now extend the focus to IA infrastructure and automated agents. The operational lesson is clear: the simple presence of a unit in node _ modules can be a vector of commitment when that unit runs code in installation hooks or in pipelines with extensive permissions. Review publishing policies, minimize privileges in CI tokens and set up secret detection in repositories are measures that significantly reduce the risk that a similar incident will scale within an organization.

Coverage

Related

More news on the same subject.