According to The Hacker News, the npm package tensorlake, a TypeScript SDK for Tensorlake applications and cloud services, was compromised in a ChainDrop / Shai-Hulud supply chain attack. The malicious release, version 0.5.144, contained obfuscated malware designed to harvest credentials, exfiltrate secrets, establish persistence, and execute remotely supplied code. The package has since been removed from the npm registry.
Socket's analysis found that the compromised release included a preinstall hook that launched a JavaScript file, which in turn loaded an obfuscated credential-stealing and self-propagating worm using the Bun runtime. The malware targets npm tokens, GitHub tokens, AWS credentials, HashiCorp Vault, Kubernetes credentials, SSH keys, .env files, cryptocurrency wallets, messaging app data, and configuration or MCP files associated with Anthropic Claude, Cursor, Kiro, Windsurf, and Zed. It also drops the HackBrowserData binary, exfiltrates collected data, establishes persistence, and enables remote code execution.
StepSecurity reported that malicious files were pushed to the main branch of the tensorlakeai/tensorlake repository under a maintainer's name, with the first rogue commit occurring on October 7, 2026, at 01:20 a.m. UTC. The repository's release workflow published version 0.5.144 to npm a day later. To propagate, the worm enumerates packages tied to the victim's publishing identity, builds Sigstore provenance, and republishes compromised versions. It also writes .claude/settings.json and .vscode/tasks.json files into reachable repositories, so the malware runs again when a project is opened in Claude Code or VS Code. The malware uses an Ethereum contract to resolve its command-and-control endpoint, with GitHub acting as a fallback for staging stolen data, and includes a "hostage token" component that can execute a destructive routine if the victim revokes the stolen GitHub token.
ChainDrop was first documented in early August 2026 in connection with the compromise of hundreds of npm packages, including Keyv and Cacheable, which contained a Mini Shai-Hulud variant. This incident extends the supply chain attack to AI agent infrastructure. Users who installed the malicious version are advised to remove it immediately and rotate their credentials.