The credential-stealing malware 'Shai-Hulud' compromised AI infrastructure platform Tensorlake via an npm package, detected within minutes of release; actual impact remains unknown.
The credential-hijacking Shai-Hulud worm has compromised a recent release of the npm package for Tensorlake's SDK, version 0.5.144. Multiple security researchers detected the infection on Thursday. With approximately 12,000 downloads per week and over a thousand GitHub stars, the SDK's popularity means the malicious version poses significant risk to its user base.
Analysis reveals the infected package shares code and techniques with ChainDrop, a Shai-Hulud variant that compromised npm dependencies including keyv and flat-cache in August. Like other Shai-Hulud variants, this version is engineered to steal credentials and self-propagate. According to supply chain security firm SafeDep, it targets crypto wallets, browser passwords, GitHub Actions secrets, cloud credentials, and service-account tokens—harvesting and exfiltrating them while maintaining an open channel to its command-and-control infrastructure for further instructions.
The variant includes a particularly malicious feature: it monitors stolen GitHub tokens and, if one is revoked, can trigger deletion of the infected user's home directory under specific conditions, complicating removal efforts. Socket recommends rebuilding compromised systems from a trusted source before restoring access to secrets, while researchers advise disabling the malicious token monitor before revoking affected credentials.
Tensorlake is a cloud-native platform for running isolated AI agents and untrusted AI-authored code, with the infected SDK used to create and manage Tensorlake environments. Socket warns that the SDK's installation script executes on the developer's machine or build server, outside Tensorlake's sandbox protections, potentially compromising the host before any AI-generated code runs. "Teams may isolate an agent's generated code while installing its SDK on a developer workstation, application server, or build runner with access to deployment credentials and other secrets," Socket noted. "Code executed during that installation inherits the permissions of the installing process."
The malicious version had limited exposure time. According to Socket, the infected package was published to npm early Thursday morning UTC and flagged by its detection engine eleven minutes later. npm removed the version, and Tensorlake pulled the package, releasing version 0.5.145 as a replacement. Tensorlake users should verify they have not installed the compromised version.