hacker-news · Crawled Oct 8, 2026
Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm
4 IoCs 1 Malware
Read original article ↗
AI Summary
The npm package 'tensorlake' was compromised in a supply chain attack delivering a credential-stealing and self-propagating worm named Shai-Hulud. The malicious version 0.5.144 includes a preinstall hook that executes an obfuscated JavaScript loader, which deploys malware to harvest credentials from npm, GitHub, AWS, Kubernetes, Vault, SSH keys, and cryptocurrency wallets. The malware establishes persistence, exfiltrates data via GitHub repositories, uses Ethereum for C2 resolution, and can trigger destructive actions if stolen tokens are revoked. It also modifies project files in AI development environments to re-execute upon project access.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 4 extracted
| Type | Value | Detail |
|---|---|---|
| Package | [email protected] | Details → |
| Filename | package/lib/setup.mjs | Details → |
| Filename | package/lib/Math_Symbol.js | Details → |
| Domain | iseekaigogo[.]com | Details → |
MITRE ATT&CK TTPs 29 techniques
T1021 Remote Services · Lateral Movement T1021.003 Distributed Component Object Model · Lateral Movement T1055 Process Injection · Defense Evasion T1059.001 PowerShell · Execution T1059.007 JavaScript · Execution T1068 Exploitation for Privilege Escalation · Privilege Escalation T1071 Application Layer Protocol · Command And Control T1071.001 Web Protocols · Command And Control T1071.003 Mail Protocols · Command And Control T1078 Valid Accounts · Defense Evasion T1078.004 Cloud Accounts · Defense Evasion T1081 T1081 T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1086 T1086 T1090 Proxy · Command And Control T1098 Account Manipulation · Persistence T1105 Ingress Tool Transfer · Command And Control T1133 External Remote Services · Persistence T1195 Supply Chain Compromise · Initial Access T1195.001 Compromise Software Dependencies and Development Tools · Initial Access T1195.002 Compromise Software Supply Chain · Initial Access T1485 Data Destruction · Impact T1528 Steal Application Access Token · Credential Access T1530 Data from Cloud Storage · Collection T1552 Unsecured Credentials · Credential Access T1553 Subvert Trust Controls · Defense Evasion T1555 Credentials from Password Stores · Credential Access T1566 Phishing · Initial Access