Shai-Hulud worm makes jump to AI infrastructure with Tensorlake compromise
Shai-Hulud infected Tensorlake’s npm SDK 0.5.144, stealing credentials before the package was removed within minutes.
Researchers found the Shai-Hulud credential-hijacking worm in Tensorlake SDK npm package 0.5.144, which has about 12,000 weekly downloads. The ChainDrop-related build steals crypto wallets, browser passwords, GitHub Actions secrets, cloud credentials, and service-account tokens, then keeps a command-and-control channel. Socket says it was flagged 11 minutes after publication; npm and Tensorlake removed it and released 0.5.145. The installer can execute on a developer machine or build server outside Tensorlake’s sandbox, and a token monitor may delete a home directory if certain GitHub tokens are revoked.