Build2 publishersIndependently confirmed2 min readPublished
In Tensorlake's npm SDK 0.5.144, a preinstall hook steals credentials before any sandbox runs
Tensorlake's npm SDK 0.5.144 runs a credential-stealing worm from a preinstall hook at install time, Socket reported. According to Socket's analysis, any secret reachable from a workstation or build runner that installed the release may be exposed.
The Engineer · Build desk

What happened
- Socket flagged the release at 01:23:10 UTC on October 8, 2026, about 11 minutes after it was published at 01:12:07 UTC.
- lib/setup.mjs, an obfuscated loader invoked by the hook, uses Bun to launch the worm payload in lib/Math_Symbol.js.
- Collection targets include npm and GitHub tokens, AWS credentials from IMDS, ECS, Secrets Manager and SSM, local Vault and Kubernetes credentials, SSH keys and .env files.
- To spread, the worm lists packages tied to the victim's publishing identity, builds Sigstore provenance and republishes compromised versions of them.
- Those filenames and the install hook match the August ChainDrop / Shai-Hulud compromises of keyv, cacheable and related npm packages.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- decision Teams that install the SDK on build runners holding deploy credentials now have to decide whether dependency lifecycle scripts run on those runners at all, since the hook executes only where they are permitted.
- exposure Developers building agents stand to lose more than cloud keys, because configuration and MCP files for .claude, .cursor, .kiro, Windsurf and Zed are on the payload's collection list.
- constraint Blocking one command-and-control domain will not cut the payload off, because it looks up its endpoint through an Ethereum contract over about 30 public RPC endpoints, with GitHub as a fallback.
- constraint A Sigstore provenance attestation on a package republished from a victim's account cannot be taken as evidence the code is clean, because the worm generates that provenance itself.
The trigger is one entry in the published manifest: `"preinstall": "node lib/setup.mjs"` [6]. Where dependency lifecycle scripts are permitted, that line runs during installation [7]. Nobody has to import the SDK or start an agent for it to fire [7].
Tensorlake's product is isolation. The company sells sandboxes for untrusted, LLM-generated code, with checkpointing, suspend and resume, and its npm SDK creates and manages those environments from TypeScript [3]. The sandbox is built to contain the agent's output, and at install time the agent has produced nothing [3][7]. "A compromised SDK creates exposure on the machine installing it, before generated code reaches a sandbox," the Socket Research Team wrote [4]. According to Socket, that machine can be a developer workstation, an application server or a build runner with access to deployment credentials [16]. Code executed during the install inherits the permissions of the installing process [10].
The package gets about 12,000 weekly downloads and has more than 1,000 stars on GitHub [19]. Socket points out that the download figure describes overall usage and does not measure downloads of 0.5.144 or confirmed infections [20].
Scoping starts with lockfiles and CI install logs. The question for each machine is whether it resolved 0.5.144 in an install that ran lifecycle scripts [1][7]. Uninstalling the package does not end the matter: Socket says the payload's persistence can keep attacker access after the dependency is removed [15]. Strings in the payload referencing a fake Copilot/Dependabot workflow suggest it also plants GitHub Actions workflows, according to Socket [18]. I think the right response for an affected machine is to rotate every credential it could reach, starting with npm tokens [11]. Stolen publishing credentials are what let the August wave of this campaign spread to additional packages [9].
What to watch
- Whether Tensorlake publishes a clean release and an account of how the publishing credential behind 0.5.144 was obtained.
- New npm releases republished with Sigstore provenance under identities harvested from machines that installed 0.5.144.
- Socket's fuller analysis of the Ethereum contract resolver and whether its RPC and GitHub fallback paths can be disrupted.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence74
- Adoption20
- Hype gap+5
- Incentives40
- Confidence72
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Socket detected that tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud supply chain attack, delivering credential-stealing malware.
ReportedSupportedSource: Socket Research Team2 sources— create a free account to open themView cited source - [2]
Version 0.5.144 contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code.
ReportedSupportedSource: Socket Research Team2 sources— create a free account to open themView cited source - [3]
Tensorlake provides isolated sandboxes for running untrusted, LLM-generated code, with checkpointing, suspend, and resume capabilities; its npm SDK lets developers create and manage those environments from TypeScript applications.
ReportedSupportedSource: Socket Research Team2 sources— create a free account to open themView cited source - [4]
A compromised SDK creates exposure on the machine installing it, before generated code reaches a sandbox.
ReportedSupportedSource: Socket Research Team, written2 sources— create a free account to open themView cited source - [5]
The malicious version was published on October 8, 2026, at 01:12:07 UTC. Socket flagged it at 01:23:10 UTC, approximately 11 minutes after publication.
ReportedSupportedSource: Socket Research Team2 sources— create a free account to open themView cited source - [6]
The affected release's published package manifest contains a preinstall hook: "preinstall": "node lib/setup.mjs".
ReportedSupportedSource: Socket Research Team2 sources— create a free account to open themView cited source - [7]
Where dependency lifecycle scripts are permitted, the hook gives the malicious loader an execution path during installation; developers do not need to import the SDK or start an agent for the hook to run.
ReportedSupportedSource: Socket Research Team2 sources— create a free account to open themView cited source - [8]
Socket flagged two files: package/lib/setup.mjs, an obfuscated loader invoked by the preinstall hook that launches the payload using Bun, and package/lib/Math_Symbol.js, the obfuscated credential-stealing and self-propagating worm payload.
ReportedSupportedSource: Socket Research Team2 sources— create a free account to open themView cited source - [9]
The installation hook and payload filenames match the structure documented in the August ChainDrop / Shai-Hulud compromises of keyv, cacheable, and related npm packages, where stolen publishing credentials enabled the worm to spread to additional packages.
ReportedSupportedSource: Socket Research Team2 sources— create a free account to open themView cited source - [10]
Code executed during installation inherits the permissions of the installing process.
ReportedSupportedSource: Socket Research Team2 sources— create a free account to open themView cited source - [11]
The payload's collection targets include npm tokens (.npmrc files, the npm token API, OIDC token exchange), GitHub tokens checked for repository and workflow permissions, AWS credentials and secrets via IMDS, ECS, Secrets Manager and SSM, HashiCorp Vault at 127.0.0.1:8200, Kubernetes service-account tokens and kubeconfig files, SSH keys, .env files, cryptocurrency wallets and messaging app data.
ReportedSupportedSource: Socket Research Team2 sources— create a free account to open themView cited source - [12]
To propagate, the worm enumerates packages associated with the victim's publishing identity, builds Sigstore provenance, and republishes compromised versions.
ReportedSupportedSource: Socket Research Team2 sources— create a free account to open themView cited source - [13]
Any secrets accessible to the executing process may be exposed.
ReportedSupportedSource: Socket Research Team2 sources— create a free account to open themView cited source - [14]
The payload has no hardcoded command-and-control domain; it resolves its endpoint through an Ethereum contract using approximately 30 public RPC endpoints, with a GitHub fallback.
ReportedSupportedSource: Socket Research Team2 sources— create a free account to open themView cited source - [15]
Persistence can retain attacker access after the affected dependency is removed.
ReportedSupportedSource: Socket Research Team2 sources— create a free account to open themView cited source - [16]
Teams may isolate an agent's generated code while installing its SDK on a developer workstation, application server, or build runner with access to deployment credentials and other secrets.
ReportedSupportedSource: Socket Research Team2 sources— create a free account to open themView cited source - [17]
The payload targets configuration and MCP files associated with AI development tools .claude, .cursor, .kiro, Windsurf, and Zed.
ReportedSupportedSource: Socket Research Team2 sources— create a free account to open themView cited source - [18]
Strings referencing a fake Copilot/Dependabot workflow suggest the worm also plants GitHub Actions workflows.
ReportedSupportedSource: Socket Research Team2 sources— create a free account to open themView cited source - [19]
The tensorlake package receives approximately 12K weekly downloads and has over 1k stars on GitHub.
- [20]
The 12K weekly download figure describes the package's overall usage; it does not measure downloads of the malicious version or confirmed infections.
Sources
2 independent publishers whose own reporting we read for this story.
- socket.devTensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
1 article · October 7, 2026
- thehackernews.comTensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm
1 article · October 7, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.