Popular Developer Package Hijacked to Spread Self-Replicating Credential-Stealing Worm
Version 0.5.144 of the npm package "tensorlake", a TypeScript software development kit for Tensorlake applications, sandboxes and cloud services, was compromised in a supply chain attack linked to the ChainDrop / Shai-Hulud campaign. Security firm Socket reports that the malicious release contained obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence and runs remotely supplied code. The version has since been removed from the npm registry.
The malware targets credentials in local files, CI environments, Kubernetes and Vault sources, and sends the stolen data to the attacker. Socket warns that any secrets accessible to the running process may be exposed, and that persistence can keep attacker access alive even after the affected dependency is removed. The worm also spreads: it finds other packages tied to the victim's publishing identity and republishes compromised versions. Strings in the code suggest it may also plant fake Copilot/Dependabot workflows in GitHub Actions.
A further "hostage token" component keeps checking whether a stolen GitHub token is still valid. If the victim revokes the token, the malware runs attacker-supplied PowerShell code that is likely designed to trigger a destructive routine, a tactic seen in earlier Shai-Hulud waves. The malware resolves its command-and-control address through an Ethereum contract, and uses public GitHub repositories as a fallback to stage encrypted stolen data.