# tensorlake@0.5.144 Is Malicious: A Shai-Hulud Worm That Holds Your GitHub Token Hostage > A compromised release of the tensorlake npm SDK (version 0.5.144) carries a Shai-Hulud / ChainDrop-family worm. A preinstall hook runs setup.mjs, skips CI so it lands on developer laptops, pulls the Bun runtime and executes an obfuscated payload that steals GitHub and npm tokens, cloud keys, Kubernetes and Vault secrets, SSH keys, browser logins and AI-tool configs, then republishes itself into every package the stolen npm token can reach. The twist: a “gh-token-monitor” service wipes the home directory if you revoke the stolen GitHub token. Safe version to pin: 0.5.143. Developing story — what’s confirmed, what isn’t, and the order of operations for cleanup. Source: https://playciso.com/blog/tensorlake-npm-0-5-144-shai-hulud-worm-hostage-token · Published: 2026-10-08 · Publisher: PlayCISO (https://playciso.com) Primary source: https://www.stepsecurity.io/blog/tensorlake-npm-compromised-hostage-token-worm --- The Shai-Hulud worm has a new host. **tensorlake@0.5.144** — the npm SDK for Tensorlake’s AI agent and document-processing infrastructure — shipped with a credential-stealing, self-republishing payload, and this variant adds something the earlier waves didn’t: a **dead-man’s switch** that wipes your home directory if you revoke the token it stole. This is a developing incident and the full picture is still being assembled, so we’ll keep the usual discipline: what is _confirmed_, what is _reported or early_, and then what a security leader should actually do — in the right order, because this time the order matters. ## What is confirmed - A malicious version shipped. tensorlake@0.5.144 carries a worm in the Shai-Hulud / ChainDrop family, flagged by Socket and StepSecurity on 8 October 2026. StepSecurity names 0.5.143 as the safe version to pin. - How it runs. A preinstall hook executes setup.mjs. The script detects CI and skips itself there — this one is aimed at developer laptops, not runners. It downloads the Bun runtime and uses it to execute an obfuscated payload of roughly 856 KB placed under typescript/lib/. - What it takes. GitHub and npm tokens, cloud keys, Kubernetes and Vault secrets, SSH keys, saved browser logins, and the config files of AI coding tools — Claude, Cursor and Windsurf — which increasingly hold API keys of their own. - How it spreads. With a stolen npm token it downloads the victim’s own packages, injects itself, bumps the version and republishes them. That is the Shai-Hulud signature: every infected maintainer becomes a new publisher. - The hostage token. It installs a persistent “gh-token-monitor” service. If the stolen GitHub token is revoked, the service runs rm -rf against the home directory. The first thing most people do after a credential theft is now the thing that destroys the machine. - It looked legitimate. Socket reports the release came through the repository’s own release workflow and therefore carries a valid npm provenance attestation. Provenance proves where a package was built, not that the source it was built from was clean. ## What is reported or still early - Initial access. Reporting describes the attacker gaining access to the tensorlake GitHub repository and introducing the code via verified maintainer commits and a direct file upload, with the npm publish following roughly 20 hours later. Treat the timeline as reported, not forensically final. - Command and control. The C2 address is resolved through an attacker-controlled Ethereum wallet, a technique seen in earlier waves; the most recent transaction pointed at iseekaigogo[.]com. Expect it to change. - Early-detection indicators. The setup.mjs preinstall file is the clearest marker. Early triage has also pointed at a Math_Symbol.js file inside the package; we have not yet seen that filename independently confirmed by a published analysis, so treat it as a lead to check in the package’s file listing rather than a settled IOC. - Blast radius. How many downstream packages the worm has republished into is not yet known. The honest answer today is “more than tensorlake.” ## The detail that should change your runbook: order of operations Every incident playbook says _revoke first_. This variant is built to punish that. The `gh-token-monitor` service is persistence _plus_ a tripwire: it polls the stolen GitHub token, and the moment the token stops working it wipes `~/`. So the sequence has to be: **find the implant → remove the persistence (and preserve evidence if you need it) → then revoke and rotate**. Socket’s warning is blunt: removing the npm dependency does not remove the implant. The wider point is the one we made about [@subql](/blog/subql-shai-hulud-chaindrop-npm-worm-supply-chain-2026) two days ago and [keyv](/blog/keyv-shai-hulud-npm-compromise-provenance) before that: this is no longer a leaked-secret problem, it is a **trust-and-blast-radius** problem. A valid provenance attestation on a malicious release is the proof. ## The defender’s playbook - ☐ Find it. npm ls tensorlake on every repo and developer machine; grep package-lock.json, pnpm-lock.yaml and yarn.lock for 0.5.144. Don’t forget transitive dependencies and anything an AI coding agent installed on your behalf. - ☐ Remove persistence before you revoke. Locate and stop the gh-token-monitor service on any host that ran the install, then rotate GitHub, npm, cloud, Kubernetes, Vault, SSH and browser-saved credentials. In that order. - ☐ Pin and block. Pin to 0.5.143 (or remove the dependency), and run installs with --ignore-scripts by default — the pnpm/yarn equivalents exist — allowlisting the few packages that genuinely need lifecycle hooks. A preinstall hook that never runs steals nothing. - ☐ Check what you publish. If any maintainer in your org ran the bad version, look at your own npm packages for versions you didn’t cut. The worm republishes through stolen tokens. - ☐ Audit the AI-tool configs. Claude, Cursor and Windsurf config files were on the target list. Rotate the API keys stored there and in any MCP server configs on affected machines. - ☐ Scan continuously. Point PlayCISO’s NPM Scanner → and Package Scanner → at your manifests and the AI Dependency Scanner → at your AI stack, so the next malicious version is caught at install time, not audit time. Keep a live AIBOM → so “are we exposed?” takes minutes. - ☐ Rehearse the wipe scenario. “A dev laptop has a dead-man’s switch on a stolen token — who touches it first, and in what order?” is a tabletop worth running in the War Room → before it’s a real Tuesday. ## The takeaway tensorlake@0.5.144 is the same worm with a sharper edge: it skips CI to land on the humans, it carries a valid provenance stamp, and it has made your incident playbook’s first step into a trap. Default-deny install scripts, pin what you consume, fence what you publish, and update the runbook so _remove persistence_ comes before _revoke_. We’re tracking the full analysis and will update this post as the details are confirmed. _Scan your dependencies free with the [NPM Scanner](/tools/npm-scanner) and [Package Scanner](/tools/package-scanner), and rehearse the response in the [War Room](/warroom). Earlier in this series: [@subql and ChainDrop](/blog/subql-shai-hulud-chaindrop-npm-worm-supply-chain-2026), [keyv and the provenance problem](/blog/keyv-shai-hulud-npm-compromise-provenance)._