Tensorlake npm Package Compromised to Spread Shai-Hulud Worm and Steal Developer Secrets
Malicious tensorlake@0.5.144 on npm delivers a Shai-Hulud worm that steals developer secrets and can wipe hosts.
Aikido reported that npm package tensorlake version 0.5.144, published on 8 October 2026, contains a new Shai-Hulud worm variant. A preinstall script downloads the Bun runtime and runs an obfuscated payload that harvests cloud, CI/CD, SSH, Vault, GitHub, browser, and cryptocurrency-wallet secrets. Stolen data can be sent to iseekaigogo[.]com or to an address retrieved from an actor-controlled Ethereum contract. The payload can also wipe infected machines if an embedded GitHub token is revoked; PyPI and Cargo distributions were not compromised.