TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Blog post from Socket
Socket Research reported that Tensorlake’s npm SDK version 0.5.144, published on October 8, 2026, was compromised in a ChainDrop/Shai-Hulud supply-chain attack and contained obfuscated credential-stealing malware executed automatically through a preinstall script. The malware targets npm, GitHub, AWS, Kubernetes, HashiCorp Vault, SSH, environment files, cryptocurrency wallets, messaging applications, and AI development-tool configurations, while also exfiltrating data, establishing persistence, running remotely supplied code, and attempting to spread by republishing packages associated with stolen npm publishing credentials. Its command-and-control endpoint is resolved through an Ethereum smart contract and public RPC providers rather than a fixed domain, and a persistent “hostage token” monitor can execute an attacker-controlled command when a stolen GitHub token is revoked, reportedly risking deletion of the affected user’s home directory. Organizations are advised to identify installations of [email protected], isolate potentially affected hosts, remove the token-monitor persistence before revoking credentials, investigate unauthorized account activity and package publications, rotate exposed secrets, and rebuild compromised systems from trusted sources.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 8 | No monthly metrics for this publish month. | |||
| AI Agents | 4 | No monthly metrics for this publish month. | |||
| Kubernetes | 3 | No monthly metrics for this publish month. | |||
| AI Coding Assistant | 1 | No monthly metrics for this publish month. | |||
| LLM | 1 | No monthly metrics for this publish month. | |||
| MCP | 1 | No monthly metrics for this publish month. | |||
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.