The news
A malicious version of the Tensorlake npm package, the JavaScript software kit for the Tensorlake AI agent platform, was published early on October 8, 2026, carrying a variant of the Shai-Hulud credential-stealing worm, according to security firm Socket and The Register.
Socket said the compromised release, version 0.5.144, was published at 01:12 UTC and that its scanner flagged it at 01:23 UTC, about 11 minutes later. The package sees roughly 12,000 downloads a week, and the project has more than 1,000 stars on GitHub, Socket said. The Register reported that npm pulled the bad version and that Tensorlake shipped version 0.5.145 the same day.
The attack ran at install time. According to Socket, a preinstall hook, a script that npm runs automatically when a package is installed, launched obfuscated loader code that then started the credential stealer. The Register noted that this happened on developer laptops or build servers, outside the sandbox Tensorlake uses to run AI-generated code.
Socket said the payload went after npm tokens, GitHub credentials, AWS secrets, HashiCorp Vault data, Kubernetes configuration files, SSH keys and AI development tools, and could spread itself by publishing through victims' own npm accounts. The Register reported it also targets cryptocurrency wallets, browser passwords and GitHub Actions secrets.
The Register also described a destructive feature: the malware monitors stolen GitHub tokens and can delete a victim's home directory if those tokens are revoked. Both Socket and The Register advised disabling that monitoring before revoking credentials, then rebuilding affected machines from trusted sources before restoring secrets.
The Register linked the code to the ChainDrop variant, which it said was used in August 2026 to compromise the keyv and flat-cache npm packages. Multiple researchers reported the infection, with Socket and SafeDep publishing analysis, according to The Register.
The numbers
- Compromised version
- tensorlake 0.5.144
- Time to detection (Socket)
- About 11 minutes
- Weekly downloads
- About 12,000
- Clean version
- 0.5.145
Why CEOs should care
CISOs should treat any machine that installed tensorlake 0.5.144 as compromised, not just the project that used it. The worm targets the keys that matter most: cloud accounts, CI/CD secrets and package-publishing tokens. The order of operations matters here, since revoking a GitHub token before disabling the malware's watcher can trigger deletion of the home directory, according to The Register and Socket.
Engineering leaders building with AI agents should note where the risk actually sat. Tensorlake's sandbox was designed to contain AI-generated code, but the attack ran during installation, before any of that applied. Ask teams whether build servers can run install scripts by default, whether dependency versions are pinned, and whether new releases are held for a cooling-off period before they reach production pipelines.
For boards and CFOs, the business question is blast radius. A single stolen publishing token lets the worm push malicious versions of your own packages to your customers. Ask whether developer and CI credentials are short-lived, scoped to one purpose, and monitored for unusual publishing activity.
The bigger picture
Shai-Hulud-style worms have repeatedly hit the npm registry, and this incident shows them moving into tooling for AI agents, where developers often hold broad cloud and model-provider credentials. The pace cuts both ways: Socket caught this release in minutes, but any automated build that pulled it in that window would still have run the payload.
The broader lesson is that AI platforms inherit the same open-source supply chain risks as any other software, and their sandboxes protect runtime, not installation.
What’s next
Teams should search lockfiles and build logs for tensorlake 0.5.144, follow the remediation order Socket published, and watch for further compromised packages, since the worm is designed to spread through stolen publishing accounts.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error
Companies in this story







