Read as article
Tensorlake npm Worm Sets Hostage Token Trap That Wipes Home Directory
By @sharedot · · 8 pages
- Programming
- Npm
- Supply Chain Security
- Malware
A malicious tensorlake@0.5.144 release spread the Shai-Hulud worm with a hostage GitHub token whose revocation wipes the victim's home directory.
What happened: a poisoned SDK release from the project's own pipeline
Attackers pushed malicious commits directly to the main branch of tensorlakeai/tensorlake under a maintainer's name, starting at 01:20 UTC on October 7, then let the repository's own release workflow publish tensorlake@0.5.144 to npm at 01:12 UTC on October 8. The package, a TypeScript SDK with more than 12,000 weekly downloads, carried a preinstall hook that runs an obfuscated loader and an 856 KB payload when developers install it. Because the build came from the real repo, the release even carried a valid npm provenance attestation. StepSecurity detected the release and reported it to maintainers in GitHub issue #1014.
Why it is surprising: the hostage token
The malware installs a service called gh-token-monitor that checks a stolen GitHub token against the GitHub API every 60 seconds for up to 24 hours. If GitHub rejects the token — meaning the victim revoked it — the service runs `rm -rf ~/` on Linux and macOS, or deletes the user profile via PowerShell on Windows. The obvious first response, revoking the credential, is exactly what detonates the trap. OX Security reports the kill-switch string is the same one used in the May TanStack attack: `IfYouRevokeThisTokenItWillWipeTheComputerOfTheOwner`.
The evidence: what it steals and how it spreads
The payload targets GitHub and npm tokens, AWS, GCP and Azure cloud keys, Kubernetes, Docker and HashiCorp Vault credentials, SSH keys, saved browser logins, .env files, and configuration for AI tools including Claude, Cursor, Windsurf, Kiro and Zed. It skips CI environments, making developer machines the real target, and exfiltrates data to iseekaigogo.com or to a public GitHub repo it creates in the victim's account, described as "Shai-Hulud: Here We Go Again." Endor Labs reports an Ethereum contract address serves as an on-chain dead-drop resolving the C2 domain. To spread, it republishes every package the victim can publish to with the worm inside, and commits .claude/settings.json and .vscode/tasks.json files to reachable repos so it reruns in Claude Code or VS Code.
The stakes: provenance can no longer be trusted as a safety signal
A valid provenance attestation only proves where a package was built, not that the code is safe — and here the attacker corrupted the source first, then let the trusted pipeline vouch for the result. Socket, cited by news.lavx.hu, says the republished packages even carry Sigstore provenance, making poisoned versions look legitimately signed. The worm follows the ChainDrop campaign first documented in early August 2026, and extends it into AI agent infrastructure, where coding agents store MCP configuration, API keys and editor-level credentials on disk. Any machine that installed 0.5.144 must be treated as fully compromised.
Remediation: remove the monitor before you rotate
StepSecurity's remediation is strictly ordered: never revoke a GitHub token until the monitor is gone. First check for the package with `npm ls tensorlake` and lockfile searches, then pin to 0.5.143, delete node_modules and clean the npm cache, and consider `ignore-scripts=true`. Look for `~/.config/gh-token-monitor/` and stop the service via systemctl on Linux, launchctl on macOS, or Task Scheduler on Windows. Only then rotate npm, GitHub, cloud, Vault, Kubernetes and SSH credentials and saved browser passwords. Endor Labs reports version 0.5.144 has since been removed from npm, and that the six tensorlake-native-* platform binaries contained no payload.
What comes next: a brand that outlived its creators
OX Security notes the Shai-Hulud name has become a brand that copycats reuse even after its original TeamPCP members were arrested in August, and that this wave uses new encryption public keys not connected to earlier variants, suggesting a new group or independent actor. Its researchers found five repositories uploaded with stolen credentials following this attack, alongside a wallet tied to an Ethereum contract holding about $12.44 in crypto. Worm-tagged packages may continue surfacing as stolen npm tokens are spent, so teams should watch lockfiles, GitHub Actions workflows referencing Copilot or Dependabot that nobody added, and any repos with the "Shai-Hulud" description.
Sources
- stepsecurity.io › Tensorlake npm Package Compromised: A Worm With a Hostage Token That Wipes Your Machine If You Revoke It
- endorlabs.com › Tensorlake npm package compromised by Shai-Hulud in latest software supply chain attack
- ox.security › “Shai-Hulud: Here We Go Again” - “tensorlake” npm Package Hit With Malware
- news.lavx.hu › Hackers poison tensorlake npm package to spread Shai-Hulud credential-stealing worm