Skip to content
TECH CEO Daily
CybersecuritySecurity Alert

Shai-Hulud worm hits Tensorlake npm SDK, stealing cloud and GitHub secrets from AI developers

A malicious Tensorlake SDK release ran a credential-stealing worm at install time, before any of the AI platform's sandbox protections could apply.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1On October 8, 2026, a malicious tensorlake npm version 0.5.144 carried a Shai-Hulud worm variant.
  • 2Socket says it flagged the release about 11 minutes after it was published; npm removed it.
  • 3The payload targets cloud keys, GitHub secrets, npm tokens and crypto wallets, and can spread through victims' accounts.

The news

A malicious version of the Tensorlake npm package, the JavaScript software kit for the Tensorlake AI agent platform, was published early on October 8, 2026, carrying a variant of the Shai-Hulud credential-stealing worm, according to security firm Socket and The Register.

Socket said the compromised release, version 0.5.144, was published at 01:12 UTC and that its scanner flagged it at 01:23 UTC, about 11 minutes later. The package sees roughly 12,000 downloads a week, and the project has more than 1,000 stars on GitHub, Socket said. The Register reported that npm pulled the bad version and that Tensorlake shipped version 0.5.145 the same day.

The attack ran at install time. According to Socket, a preinstall hook, a script that npm runs automatically when a package is installed, launched obfuscated loader code that then started the credential stealer. The Register noted that this happened on developer laptops or build servers, outside the sandbox Tensorlake uses to run AI-generated code.

Socket said the payload went after npm tokens, GitHub credentials, AWS secrets, HashiCorp Vault data, Kubernetes configuration files, SSH keys and AI development tools, and could spread itself by publishing through victims' own npm accounts. The Register reported it also targets cryptocurrency wallets, browser passwords and GitHub Actions secrets.

The Register also described a destructive feature: the malware monitors stolen GitHub tokens and can delete a victim's home directory if those tokens are revoked. Both Socket and The Register advised disabling that monitoring before revoking credentials, then rebuilding affected machines from trusted sources before restoring secrets.

The Register linked the code to the ChainDrop variant, which it said was used in August 2026 to compromise the keyv and flat-cache npm packages. Multiple researchers reported the infection, with Socket and SafeDep publishing analysis, according to The Register.

The numbers

Compromised version
tensorlake 0.5.144
Time to detection (Socket)
About 11 minutes
Weekly downloads
About 12,000
Clean version
0.5.145

Why CEOs should care

CISOs should treat any machine that installed tensorlake 0.5.144 as compromised, not just the project that used it. The worm targets the keys that matter most: cloud accounts, CI/CD secrets and package-publishing tokens. The order of operations matters here, since revoking a GitHub token before disabling the malware's watcher can trigger deletion of the home directory, according to The Register and Socket.

Engineering leaders building with AI agents should note where the risk actually sat. Tensorlake's sandbox was designed to contain AI-generated code, but the attack ran during installation, before any of that applied. Ask teams whether build servers can run install scripts by default, whether dependency versions are pinned, and whether new releases are held for a cooling-off period before they reach production pipelines.

For boards and CFOs, the business question is blast radius. A single stolen publishing token lets the worm push malicious versions of your own packages to your customers. Ask whether developer and CI credentials are short-lived, scoped to one purpose, and monitored for unusual publishing activity.

The bigger picture

Shai-Hulud-style worms have repeatedly hit the npm registry, and this incident shows them moving into tooling for AI agents, where developers often hold broad cloud and model-provider credentials. The pace cuts both ways: Socket caught this release in minutes, but any automated build that pulled it in that window would still have run the payload.

The broader lesson is that AI platforms inherit the same open-source supply chain risks as any other software, and their sandboxes protect runtime, not installation.

What’s next

Teams should search lockfiles and build logs for tensorlake 0.5.144, follow the remediation order Socket published, and watch for further compromised packages, since the worm is designed to spread through stolen publishing accounts.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

TensorlakeShai-HuludSocketnpmSoftware supply chain

Earlier coverage of GitHub

All GitHub coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.