tensorlake 0.5.144: npm worm steals tokens and may wipe hosts
tensorlake npm Shai-Hulud credential worm

tensorlake 0.5.144: npm worm steals tokens and may wipe hosts

The tensorlake npm package, version 0.5.144, was published on 8 October 2026 with a self-spreading credential worm. The release came from the project's own pipeline after rogue commits landed on main the day before. npm has since pulled that version. Anyone who installed it still has a problem.

What happened

StepSecurity says the first malicious commit hit tensorlakeai/tensorlake at 01:20 UTC on 7 October, under a maintainer name, with no pull request. The release workflow then published 0.5.144. A preinstall hook runs an obfuscated loader that harvests secrets and can execute remotely supplied code.

Stolen material includes npm tokens, GitHub tokens, AWS credentials, Vault and Kubernetes secrets, SSH keys, dotenv files, wallet data, and MCP or editor config for tools such as Claude and Cursor. With a stolen npm token the worm republishes itself into the victim's other packages. A separate monitor watches the stolen GitHub token. If the victim revokes it, the monitor can run a destructive routine. That is the hostage.

Who is affected

Developers, CI runners, and build agents that installed tensorlake 0.5.144. Downstream users of any package the worm republished are in scope until those releases are identified and yanked. AI-sandbox and agent SDKs are now a normal supply-chain target, not a side case.

  • Malicious version: tensorlake 0.5.144. It is no longer on the registry.
  • Trigger: preinstall, so a routine install is enough.
  • Blast radius: every secret the process could read, plus packages that identity can publish.

What to do now

Remove 0.5.144, isolate the host, and rotate every token it could see before you revoke the GitHub token from a still-infected machine. Check npm and GitHub for unexpected publishes and for a public repo described as a Shai-Hulud drop. Pin dependencies, and block this version in the private registry. Do not treat a yanked package as a cleaned laptop.

Source: StepSecurity, Tensorlake npm Package Compromised: A Worm With a Hostage Token.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

ARTEX: AI pentest tool used to steal South Korean bank data
ARTEX agentic pentest South Korean banks