Shai-Hulud worm makes jump to AI infrastructure with Tensorlake compromise
Shai-Hulud infected Tensorlake’s npm SDK 0.5.144, stealing credentials before the package was removed within minutes.
Researchers found the Shai-Hulud credential-hijacking worm in Tensorlake SDK npm package 0.5.144, which has about 12,000 weekly downloads. The ChainDrop-related build steals crypto wallets, browser passwords, GitHub Actions secrets, cloud credentials, and service-account tokens, then keeps a command-and-control channel. Socket says it was flagged 11 minutes after publication; npm and Tensorlake removed it and released 0.5.145. The installer can execute on a developer machine or build server outside Tensorlake’s sandbox, and a token monitor may delete a home directory if certain GitHub tokens are revoked.
- Malicious Tensorlake npm SDK 0.5.144 was flagged about 11 minutes after publication.
- Worm steals wallets, browser passwords, GitHub secrets, and cloud credentials.
- Code matches the ChainDrop Shai-Hulud variant used against npm packages.
- Install scripts can run on developer hosts outside Tensorlake’s sandbox.
- Revoking monitored GitHub tokens may delete the user’s home directory.
Full article443 words · extracted from theregister.com · click to collapse
security
Credential-stealing malware detected within minutes of npm release, but impact remains unknown
The credential-hijacking Shai-Hulud worm has struck again, this time burrowing its way into a popular AI agent platform SDK.
Multiple security researchers reported Thursday that they had detected Shai-Hulud infection in a recent release of the npm package for version 0.5.144 of Tensorlake’s SDK. That package has somewhere in the neighborhood of 12,000 downloads per week, while its GitHub repository has more than a thousand stars, suggesting it’s quite popular and that the infection could pose a serious risk to anyone who installed the malicious version.
Analysis of the malicious release suggests it shares code and techniques with the Shai-Hulud variant dubbed ChainDrop by researchers, which was used in August to compromise npm dependencies including keyv and flat-cache. Like other variants of Shai-Hulud, the worm is designed to steal credentials and self-propagate.
REG AD
This particular version, according to supply chain security firm SafeDep, is designed to steal everything from crypto wallets to browser passwords, GitHub Actions secrets, cloud credentials, service-account tokens, and whatever else it can get its hands on. It exfiltrates that data and keeps an open line to its C2 infrastructure to await further instructions.
REG AD
To make matters worse, this Shai-Hulud variant monitors certain stolen GitHub tokens and, if one is revoked, can trigger the deletion of the infected user's home directory under specific conditions, making removal tricky. Socket recommends rebuilding compromised systems from a trusted source before restoring access to secrets, while researchers warn that the malicious token monitor should be disabled before revoking affected credentials.
Tensorlake, for those unfamiliar, is a cloud-native platform for running isolated AI agents and untrusted AI-authored code. The infected npm SDK is used to create and manage Tensorlake environments. Socket warns that the malicious SDK's installation script can execute on the developer's machine or build server, outside Tensorlake's sandbox protections, potentially compromising the host before any AI-generated code is run.
“Teams may isolate an agent’s generated code while installing its SDK on a developer workstation, application server, or build runner with access to deployment credentials and other secrets,” Socket noted. “Code executed during that installation inherits the permissions of the installing process.”
That may sound bad, but it’s worth noting the malicious version wasn’t up for long - according to security firm Socket, the infected version was published to npm earlier this morning, UTC, and was flagged by its engine 11 minutes after publication. Npm removed the version, and Tensorlake has pulled the package as well, updating the version to 0.5.145. Best check to be sure you haven't installed the malicious version if you're a Tensorlake user. ®