socket-dev · Crawled Oct 8, 2026

TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack

5 IoCs
Read original article ↗

AI Summary

The npm package [email protected] was compromised in a supply chain attack linked to the ChainDrop/Shai-Hulud campaign, delivering a credential-stealing malware payload via a preinstall hook. The malicious code executes during installation, harvesting secrets from local files, CI environments, Kubernetes, Vault, and AI development tools, then exfiltrates them. The payload also establishes persistence using a 'hostage token' mechanism that triggers destructive actions if stolen tokens are revoked, and it propagates by republishing compromised npm packages under the victim's identity.

AI-extracted · verify before operational use

Indicators of Compromise 5 extracted

Type Value Detail
Package [email protected] Details →
Filename lib/setup.mjs Details →
Filename lib/Math_Symbol.js Details →
SHA-256 25a0735d0db7dc40e5d45ce42d9c106067e6a66e184d967cfecfab17c3bcb5ef Details →
SHA-256 b50a00900399ba99fb6ce1fc151519cb99d44320ef2a631f2237e1aea0ad6fec Details →