Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm
Compromised tensorlake npm 0.5.144 delivered the Shai-Hulud worm to steal secrets and spread to other packages.
Socket and StepSecurity reported that tensorlake npm version 0.5.144 was compromised in the ChainDrop/Shai-Hulud campaign and later removed from the registry. A preinstall hook launched an obfuscated Bun loader that runs a self-propagating credential worm, Math_Symbol.js. The malware steals npm, GitHub, AWS, Vault, Kubernetes, SSH, cryptocurrency, and AI-assistant secrets, drops HackBrowserData, persists, and can execute remote code. It republishes infected packages, resolves C2 iseekaigogo.com through an Ethereum contract, stages data in public GitHub repositories, and may run a destructive PowerShell handler if a stolen GitHub token is revoked.