The credential-hijacking Shai-Hulud worm has struck again. This time, the malware burrowed into a popular AI agent platform software development kit.
Multiple security researchers reported Thursday that they detected Shai-Hulud infection in version 0.5.144 of Tensorlake's npm package. That package gets roughly 12,000 downloads per week. Its GitHub repository holds over a thousand stars, which points to broad popularity.
Malware targets sensitive data
Analysis shows the malicious release shares code with the Shai-Hulud variant called ChainDrop. Researchers tracked ChainDrop to August attacks on npm dependencies like keyv and flat-cache. Like prior variants, this worm steals credentials and self-propagates.
Supply chain security firm SafeDep explains that this version steals browser passwords, crypto wallets, cloud credentials, GitHub Actions secrets, and service-account tokens. The malware exfiltrates the gathered data and keeps an open line to command-and-control infrastructure for further instructions.

Installation scripts bypass sandboxes
Socket warns that this variant monitors specific stolen GitHub tokens. If a token gets revoked, the malware can trigger the deletion of an infected user directory under specific conditions. Security firms advise disabling that token monitor before revoking affected credentials.
Tensorlake operates a cloud-native platform for isolated AI agents and untrusted code. Socket points out that the malicious SDK installation script runs on developer machines or build servers outside sandbox protections. That process compromises the host environment before AI-generated code even runs.
Read nextPoeLLM malware infects exposed AI servers in cryptomining attacksQuick removal limits exposure
The infected version of the npm package went live Thursday morning UTC. Socket reports that its engine flagged the malicious release just 11 minutes after publication. Both npm and Tensorlake pulled the compromised package quickly.
Tensorlake updated its software version to 0.5.145 to resolve the issue. Socket recommends rebuilding compromised systems from trusted sources before restoring access to secrets.



