Skip to content

Build2 publishersIndependently confirmed2 min readPublished

In Tensorlake's npm SDK 0.5.144, a preinstall hook steals credentials before any sandbox runs

Tensorlake's npm SDK 0.5.144 runs a credential-stealing worm from a preinstall hook at install time, Socket reported. According to Socket's analysis, any secret reachable from a workstation or build runner that installed the release may be exposed.

The Engineer · Build desk

How we use AISend a correction

Illustration accompanying In Tensorlake's npm SDK 0.5.144, a preinstall hook steals credentials before any sandbox runs
Generated illustration

What happened

  • Socket flagged the release at 01:23:10 UTC on October 8, 2026, about 11 minutes after it was published at 01:12:07 UTC.
  • lib/setup.mjs, an obfuscated loader invoked by the hook, uses Bun to launch the worm payload in lib/Math_Symbol.js.
  • Collection targets include npm and GitHub tokens, AWS credentials from IMDS, ECS, Secrets Manager and SSM, local Vault and Kubernetes credentials, SSH keys and .env files.
  • To spread, the worm lists packages tied to the victim's publishing identity, builds Sigstore provenance and republishes compromised versions of them.
  • Those filenames and the install hook match the August ChainDrop / Shai-Hulud compromises of keyv, cacheable and related npm packages.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • decision Teams that install the SDK on build runners holding deploy credentials now have to decide whether dependency lifecycle scripts run on those runners at all, since the hook executes only where they are permitted.
  • exposure Developers building agents stand to lose more than cloud keys, because configuration and MCP files for .claude, .cursor, .kiro, Windsurf and Zed are on the payload's collection list.
  • constraint Blocking one command-and-control domain will not cut the payload off, because it looks up its endpoint through an Ethereum contract over about 30 public RPC endpoints, with GitHub as a fallback.
  • constraint A Sigstore provenance attestation on a package republished from a victim's account cannot be taken as evidence the code is clean, because the worm generates that provenance itself.

The trigger is one entry in the published manifest: `"preinstall": "node lib/setup.mjs"` [6]. Where dependency lifecycle scripts are permitted, that line runs during installation [7]. Nobody has to import the SDK or start an agent for it to fire [7].

Tensorlake's product is isolation. The company sells sandboxes for untrusted, LLM-generated code, with checkpointing, suspend and resume, and its npm SDK creates and manages those environments from TypeScript [3]. The sandbox is built to contain the agent's output, and at install time the agent has produced nothing [3][7]. "A compromised SDK creates exposure on the machine installing it, before generated code reaches a sandbox," the Socket Research Team wrote [4]. According to Socket, that machine can be a developer workstation, an application server or a build runner with access to deployment credentials [16]. Code executed during the install inherits the permissions of the installing process [10].

The package gets about 12,000 weekly downloads and has more than 1,000 stars on GitHub [19]. Socket points out that the download figure describes overall usage and does not measure downloads of 0.5.144 or confirmed infections [20].

Scoping starts with lockfiles and CI install logs. The question for each machine is whether it resolved 0.5.144 in an install that ran lifecycle scripts [1][7]. Uninstalling the package does not end the matter: Socket says the payload's persistence can keep attacker access after the dependency is removed [15]. Strings in the payload referencing a fake Copilot/Dependabot workflow suggest it also plants GitHub Actions workflows, according to Socket [18]. I think the right response for an affected machine is to rotate every credential it could reach, starting with npm tokens [11]. Stolen publishing credentials are what let the August wave of this campaign spread to additional packages [9].

What to watch

  • Whether Tensorlake publishes a clean release and an account of how the publishing credential behind 0.5.144 was obtained.
  • New npm releases republished with Sigstore provenance under identities harvested from machines that installed 0.5.144.
  • Socket's fuller analysis of the Ethereum contract resolver and whether its RPC and GitHub fallback paths can be disrupted.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence74
Adoption20
Hype gap+5
Incentives40
Confidence72
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Socket detected that tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud supply chain attack, delivering credential-stealing malware.

    ReportedSupportedSource: Socket Research Team2 sources— create a free account to open themView cited source
  2. [2]

    Version 0.5.144 contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code.

    ReportedSupportedSource: Socket Research Team2 sources— create a free account to open themView cited source
  3. [3]

    Tensorlake provides isolated sandboxes for running untrusted, LLM-generated code, with checkpointing, suspend, and resume capabilities; its npm SDK lets developers create and manage those environments from TypeScript applications.

    ReportedSupportedSource: Socket Research Team2 sources— create a free account to open themView cited source

Sources

2 independent publishers whose own reporting we read for this story.

  1. socket.dev

    1 article · October 7, 2026

    TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
  2. thehackernews.com

    1 article · October 7, 2026

    Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Loading related stories