hacker-news · Crawled Oct 8, 2026

Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm

4 IoCs 1 Malware
Read original article ↗

AI Summary

The npm package 'tensorlake' was compromised in a supply chain attack delivering a credential-stealing and self-propagating worm named Shai-Hulud. The malicious version 0.5.144 includes a preinstall hook that executes an obfuscated JavaScript loader, which deploys malware to harvest credentials from npm, GitHub, AWS, Kubernetes, Vault, SSH keys, and cryptocurrency wallets. The malware establishes persistence, exfiltrates data via GitHub repositories, uses Ethereum for C2 resolution, and can trigger destructive actions if stolen tokens are revoked. It also modifies project files in AI development environments to re-execute upon project access.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 4 extracted

Type Value Detail
Package [email protected] Details →
Filename package/lib/setup.mjs Details →
Filename package/lib/Math_Symbol.js Details →
Domain iseekaigogo[.]com Details →

MITRE ATT&CK TTPs 29 techniques