Tensorlake npm Package Compromised: A Worm With a Hostage Token That Wipes Your Machine If You Revoke It
AI Summary
The npm package [email protected] has been compromised and functions as a malicious worm that steals credentials, including GitHub and npm tokens, cloud keys, SSH keys, and AI tool configurations. It spreads by modifying victim repositories with malicious .claude and .vscode files and republishing npm packages using stolen tokens. The malware includes a 'hostage token' mechanism: if the stolen GitHub token is revoked, a background monitor triggers deletion of the user's home directory via rm -rf ~/ or equivalent on Windows. The malicious code was pushed directly to the main branch of the tensorlakeai/tensorlake repository under a maintainer's name and published with a valid npm provenance attestation, making it appear legitimate.
AI-extracted · verify before operational use
Indicators of Compromise 6 extracted
| Type | Value | Detail |
|---|---|---|
| Package | [email protected] | Details → |
| SHA-256 | 25a0735d0db7dc40e5d45ce42d9c106067e6a66e184d967cfecfab17c3bcb5ef | Details → |
| SHA-256 | b50a00900399ba99fb6ce1fc151519cb99d44320ef2a631f2237e1aea0ad6fec | Details → |
| Domain | iseekaigogo[.]com | Details → |
| Filename | ~/.config/gh-token-monitor/ | Details → |
| Filename | ~/.local/bin/gh-token-monitor.sh | Details → |