HomeCyber BalkansHackers Exploit Tensorlake Package to Distribute Shai-Hulud Supply Chain Malware

Hackers Exploit Tensorlake Package to Distribute Shai-Hulud Supply Chain Malware

Published on

spot_img

On October 8, 2026, the cybersecurity community witnessed a significant breach as a threat actor released a compromised version of the popular npm package, tensorlake. The malicious package, specifically version 0.5.144, introduced a new variant of the self-replicating Shai-Hulud supply-chain worm, amplifying existing concerns about software supply chain security.

The implications of this malicious release are dire. The embedded malware is capable of stealing not just developer secrets but also cryptocurrency credentials that are stored within browsers. Furthermore, the worm can utilize stolen publishing credentials to propagate through interconnected software supply chains, resulting in a cascade of potential breaches affecting multiple organizations and their development environments.

This incident underscores the escalating danger that developers face with tools related to artificial intelligence (AI). A single compromise of a dependency can not only jeopardize an application’s build environment but also place sensitive assets like cloud credentials, source-control tokens, and deployment secrets at risk. This has pertinent implications for internal workflows, especially in a landscape where rapid AI development is increasingly crucial.

The malicious package executes through a preinstall lifecycle hook, triggering a function within the file lib/setup.mjs. Investigations into the matter revealed that the file contains obfuscated code, identifiable by the SHA-256 hash 25a0735d0db7dc40e5d45ce42d9c106067e6a66e184d967cfecfab17c3bcb5ef. This code subsequently downloads the Bun runtime, which allows it to run lib/Math_Symbol.js, a second-stage file that harbors the credential-stealing mechanism and worm propagation payload, discerned by the hash b50a00900399ba99fb6ce1fc151519cb99d44320ef2a631f2237e1aea0ad6fec.

A notable aspect of this attack is its sophisticated implementation. The malware sets a specific marker, termed WORMTAG, before deploying its encrypted logic. This approach differentiates the Tensorlake incident from previous Shai-Hulud campaigns, indicating a fresh compromise distinct from earlier attacks that compromised several packages by abusing maintainers’ access and npm credentials.

The earlier Shai-Hulud activities, which proliferated swiftly, affected over 444 packages and 1,381 versions in August alone. Once the payload from this latest attack is executed, it seeks to collect a wide array of sensitive information, including environment variables, local secret files, npm tokens, GitHub credentials, cloud credentials, SSH keys, Kubernetes configurations, Terraform files, and CI/CD secrets. If successful, these breaches pose a severe downstream risk. For example, compromised npm publishing tokens could allow the worm to alter packages that victims maintain, while unauthorized GitHub credentials grant access to private repositories and their automated release pipelines.

Additionally, the Tensorlake payload is equipped with a dead-man’s switch that can erase infected systems if a hardcoded GitHub token is revoked—a tactic previously observed in Shai-Hulud operations. The malware connects to the control domain iseekaigogo[.]com and is capable of fetching a new command-and-control or exfiltration address from an Ethereum smart contract, specifically 0xb614155Fd88114d40549b259457Bcf921Df091B9. This demonstrates a concern not only for code repositories but also for crucial financial data, as the malware is designed to search through hardcoded paths linked to 14 popular cryptocurrency browser extensions, proffering a direct pathway for theft of IndexedDB and LevelDB data.

This behavior further signifies a worrying trend wherein malware operators aim for direct monetization from compromised developer endpoints while simultaneously propagating through the software supply chain. The breach was traced back to Tensorlake’s GitHub repository, where an attacker managed to make verified commits using a maintainer identity. These malicious files were introduced through direct upload in commit 41b38f0. The repository was compromised for roughly 20 hours before the malicious npm publication was executed, emphasizing the rapid pace at which such vulnerabilities can be exploited.

Organizations utilizing Tensorlake should take immediate action to identify any installations of the vulnerable package, isolate possibly affected hosts, preserve forensic evidence, and rotate all credentials that may have been accessible from those systems. This list of credentials includes npm and GitHub tokens, cloud keys, CI/CD secrets, SSH keys, API credentials, cryptocurrency wallet-extension data, and browser-session tokens. It is also advisable for teams to meticulously review package publishing histories, GitHub audit logs, CI runner activity, and any unexpected modifications to package.json lifecycle scripts.

With the Tensorlake incident following a pattern observed in earlier Shai-Hulud attacks, proactive measures become essential for mitigating the risk of compromise in the ever-evolving landscape of AI and software development. The complexity and scope of these attacks highlight the critical need for robust security practices in all phases of development, as well as a heightened awareness of potential vulnerabilities that could arise from seemingly benign package dependencies.

Source link

Latest articles

Chinese Hacker Utilizes AI in Attack on South Korean Banks

A new report from CrowdStrike has unveiled a concerning cyber threat actor believed to...

FBI Takes Control of Domains Linked to Flax Typhoon Attacks

U.S. Authorities Take Action Against Chinese Cyber Intrusions In a significant move against foreign cyber...

Global Cyber Attacks Increase by 48% as Ransomware and Phishing Surge, According to Check Point

Global Cyber Attacks Surge Amid Rising Threats: A September Update In September 2026, organizations around...

Russia-Aligned UAC-0099 Develops MATCHBOIL Malware

Evolving Threat: The MATCHBOIL Downloader A cyber espionage group aligned with Russian interests has been...

More like this

Chinese Hacker Utilizes AI in Attack on South Korean Banks

A new report from CrowdStrike has unveiled a concerning cyber threat actor believed to...

FBI Takes Control of Domains Linked to Flax Typhoon Attacks

U.S. Authorities Take Action Against Chinese Cyber Intrusions In a significant move against foreign cyber...

Global Cyber Attacks Increase by 48% as Ransomware and Phishing Surge, According to Check Point

Global Cyber Attacks Surge Amid Rising Threats: A September Update In September 2026, organizations around...