Compromised 'tensorlake' npm Package Delivers Shai-Hulud Credential-Stealing Worm, Extends Supply Chain Attacks to AI Infrastructure
The npm package 'tensorlake', a TypeScript SDK for Tensorlake applications, was compromised in a ChainDrop/Shai-Hulud supply chain attack. The malicious version 0.5.144, which is no longer available, contained obfuscated malware designed to harvest credentials, exfiltrate secrets, establish persistence, and execute remotely supplied code. This malware leverages a preinstall hook to launch a JavaScript file that then executes the main credential-stealing and self-propagating worm using the Bun runtime.
This incident is significant because it extends the scope of supply chain attacks directly into AI agent infrastructure. The malware is sophisticated, capable of harvesting credentials from local files, CI environments, Kubernetes, and Vault sources. It also drops the HackBrowserData binary and writes configuration files to enable re-execution when projects are opened in Claude Code or VS Code, ensuring persistence. This means a single compromised dependency can lead to a widespread breach of an organization's development and operational environments, particularly those involved in AI/ML development.
This attack fits into a broader trend of increasingly sophisticated software supply chain compromises. Threat actors are moving beyond simple dependency confusion or typo-squatting to inject highly potent malware into widely used packages. The targeting of AI infrastructure specifically indicates a strategic shift, as AI models and their development pipelines often handle sensitive data and intellectual property. Previous incidents, such as the widespread compromise of npm packages with Mini Shai-Hulud variants, demonstrate the growing efficacy and reach of these types of attacks.
Practitioners should immediately verify if their projects have used version 0.5.144 of the 'tensorlake' package and remove it if found. Crucially, all credentials accessible to any process that might have executed this malicious package must be rotated without delay. Organizations should also review and strengthen their software supply chain security practices, including implementing stricter dependency vetting, using software composition analysis (SCA) tools, and enforcing least privilege access in CI/CD pipelines. Monitoring for unusual network activity and file modifications, especially in development environments, is also critical to detect and mitigate such advanced threats.
Read original source