
Poisoned Tensorlake npm Release Hid a Worm That Deletes Home Directories if Victims Revoke the Stolen Token
A malicious tensorlake 0.5.144, pushed to the AI sandbox company's own GitHub repository and published with valid npm provenance on October 8, steals cloud, GitHub and npm secrets, spreads through victims' packages and installs a monitor that deletes the home directory if the stolen GitHub token is revoked, so responders must remove it before rotating credentials.
Noah Park, ResponseNew York6 min read
NEW YORK - A poisoned release of tensorlake, the npm software development kit for an AI agent sandbox service, was built to steal credentials from the machines that installed it, copy itself into its victims' own packages and repositories, and leave behind a trap aimed at incident responders: a background service that deletes the user's home directory if the stolen GitHub token is revoked. Tensorlake disclosed the compromise on Thursday in a critical GitHub security advisory, after researchers at StepSecurity, Socket, Aikido and GMO Flatt Security published analyses of version 0.5.144. The company said the release "was not an authorized Tensorlake release" and that the attacker "pushed malicious code directly to our repository and published it through our own release workflow, so the package carries valid npm provenance." For SOC teams, the lesson is about sequence. The first move most responders make after a credential theft, revoking the token, is the one this malware was built to punish.
The intrusion began inside Tensorlake's own repository. StepSecurity said the first malicious commit landed on the main branch at 01:20 UTC on October 7 under a maintainer's name, followed by more commits that adjusted the payload and added a preinstall line to package.json, none of them through a pull request. Tensorlake's cleanup pull request says the payload was committed directly to main by a repository administrator account through the GitHub web interface and then released by manually dispatching the project's npm publishing workflow, which built and signed it with Sigstore provenance. Aikido estimated the repository was compromised for about 20 hours before the attacker managed to publish. Version 0.5.144 went out at 01:12:07 UTC on October 8, and Socket flagged it at 01:23:10 UTC, about 11 minutes later. Tensorlake said the package was live for about an hour and 40 minutes, from 01:12 to 02:54 UTC, that its PyPI and crates.io packages and its command-line tool were not affected, and that its user-agent monitoring had shown no usage of the bad version. Socket said the package draws about 12,000 weekly downloads, a figure that does not measure downloads of the malicious version.

The payload runs at install time. A preinstall hook calls node lib/setup.mjs, an obfuscated loader that StepSecurity said skips itself on CI systems, so developer machines are the target. It downloads the Bun JavaScript runtime and uses it to run lib/Math_Symbol.js, the worm itself, which StepSecurity described as an obfuscated 856 KB file. The researchers listed what it takes: GitHub and npm tokens, AWS and Google Cloud credentials, Kubernetes and Vault secrets, SSH and GPG keys, .env files, browser-saved passwords, cryptocurrency wallets and configuration files for AI coding tools such as Claude, Cursor and Windsurf. GMO Flatt Security said AWS Systems Manager Parameter Store and Secrets Manager were enumerated and read across all regions. Stolen data goes to a public GitHub repository the malware creates in the victim's account, described as "Shai-Hulud: Here We Go Again," or to the domain iseekaigogo[.]com. Aikido found that the malware can also look up an alternate server address by reading an Ethereum contract through public RPC services, and that it pulls the HackBrowserData tool from its server and targets 14 cryptocurrency wallet browser extensions, changes Aikido said may point to an operator focused on cashing in quickly on infected developer machines.

The worm spreads with whatever it steals. With an npm token, it downloads the victim's packages, adds itself, bumps the version and republishes them, building Sigstore provenance as it goes, according to StepSecurity and Socket. With a GitHub token, it commits .claude/settings.json and .vscode/tasks.json files into repositories the victim can write to, under a fake [email protected] author and the message "chore: update dependencies," so the code runs again when someone opens the project in Claude Code or VS Code. Tensorlake also told users to look for a branch named dependabot/github_actions/format/setup-formatter. Socket said the loader and payload file names match the August compromises of the keyv and cacheable npm packages in the campaign it calls ChainDrop, and Tensorlake placed the incident in the "Mini Shai-Hulud" campaign. Aikido said a marker unique to the tensorlake build suggests a fresh compromise rather than reinfection from an earlier wave.
Then there is the hostage token. When the malware holds a GitHub token, it installs a service called gh-token-monitor that checks the token against the GitHub API every 60 seconds for up to 24 hours, StepSecurity said. If GitHub rejects the token, the service runs rm -rf ~/, or a PowerShell deletion of the user profile on Windows. On Windows, Socket said, the monitor persists through a scheduled task that runs at logon, polls api.github.com/user and, on revocation, executes an attacker-supplied handler. The code carries the string "IfYouRevokeThisTokenItWillWipeTheComputerOfTheOwner," which Socket said had appeared in earlier Shai-Hulud waves. Socket warned that revoking the token while the monitor runs triggers the wipe "regardless of where the revocation is done."
That turns the response checklist into an ordered procedure. Tensorlake's advisory tells anyone who installed 0.5.144 with install scripts enabled, on a laptop or a CI system, to treat the machine and every credential it could reach as compromised: disconnect it from the network; remove gh-token-monitor before revoking any GitHub token; rotate credentials from a different, clean machine; check packages and repositories the tokens could touch for unexpected releases, commits authored "claude" and the rogue branch; and rebuild from a trusted image. GMO Flatt Security added a step at the top: back up data first. On Linux, removal means disabling the gh-token-monitor.service user unit and deleting ~/.config/gh-token-monitor/ and ~/.local/bin/gh-token-monitor.sh; on macOS, unloading ~/Library/LaunchAgents/com.user.gh-token-monitor.plist; on Windows, deleting the scheduled task, which StepSecurity said runs a monitor.ps1 script, and %LOCALAPPDATA%\gh-token-monitor\. Tensorlake said 0.5.143 and earlier versions are unaffected, and npm registry data shows 0.5.144 has been removed and a new 0.5.145, with no install scripts in its manifest, was published at 20:24 UTC on Thursday. StepSecurity noted that setting ignore-scripts=true in .npmrc stops install hooks like this one.

For hunters, the indicators are specific. Lockfiles and CI logs that resolved [email protected] or tensorlake-native-*@0.5.144, especially between 01:12 and 02:54 UTC on October 8; the setup.mjs hash 25a0735d0db7dc40e5d45ce42d9c106067e6a66e184d967cfecfab17c3bcb5ef and the Math_Symbol.js hash b50a00900399ba99fb6ce1fc151519cb99d44320ef2a631f2237e1aea0ad6fec; an npm install that downloads Bun; the gh-token-monitor files, user service, launch agent or logon task; DNS lookups for iseekaigogo[.]com; and new public repositories with the Shai-Hulud description or commits from the fake claude address. The vendors who caught the release sell tools that blocked it, and their posts say so, but the provenance point stands on its own. "The attestation says where a package was built," StepSecurity wrote. "It doesn't say the code is safe." Tensorlake's cleanup pull request says the company has since removed administrator bypass from its main branch rules so nobody can push directly to main, required signed commits, made every npm publish wait for a second person, and switched its CI dependency installs to run with scripts disabled.
Sources:
- GitHub: GHSA-8g63-53c9-65j2 (Tensorlake, Oct 8, 2026)
- GitHub: Pull request #1016 (Tensorlake, Oct 8, 2026)
- StepSecurity: Tensorlake npm Package Compromised (StepSecurity, Oct 8, 2026)
- Socket: TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack (Socket, Oct 8, 2026)
- Aikido: tensorlake NPM package compromised with Shai Hulud worm (Aikido, Oct 8, 2026)
- GMO Flatt Security: Software Supply Chain Attack on tensorlake (GMO Flatt Security, Oct 8, 2026)
- npm: npm registry metadata for tensorlake
Noah Park covers incident response and blue-team operations for SOCtember from New York.
Related stories
Threat Intel
Iran-Linked Hackers Posing as Dubai Airports Recruiters Hide Malware in a Visual Studio Coding Test
Response
Did You Know: Patching a KEV Host Before Collecting Evidence Can Erase the Intrusion Trail
Detection
Microsoft Tracks EvilTokens Phishing Kit Behind Device Code Token Theft
Detection