Shai-Hulud Malware Infects Tensorlake AI Agent Platform SDK
Tech

Shai-Hulud Malware Infects Tensorlake AI Agent Platform SDK

TechNews Editorial
TechNews EditorialOct 9, 2026 · 1 min read
Share

Why it matters

The incident exposes development teams to credential theft and host compromise because installation scripts execute outside sandbox protections on developer machines and build servers.

The facts

  • The Shai-Hulud credential-stealing worm infected version 0.5.144 of Tensorlake's npm SDK.
  • Security tools flagged the malicious package 11 minutes after its publication on Thursday morning UTC.
  • The npm package and Tensorlake have both pulled the compromised version and pushed an update.

The credential-hijacking Shai-Hulud worm has struck again. This time, the malware burrowed into a popular AI agent platform software development kit.

Multiple security researchers reported Thursday that they detected Shai-Hulud infection in version 0.5.144 of Tensorlake's npm package. That package gets roughly 12,000 downloads per week. Its GitHub repository holds over a thousand stars, which points to broad popularity.

Malware targets sensitive data

Analysis shows the malicious release shares code with the Shai-Hulud variant called ChainDrop. Researchers tracked ChainDrop to August attacks on npm dependencies like keyv and flat-cache. Like prior variants, this worm steals credentials and self-propagates.

Supply chain security firm SafeDep explains that this version steals browser passwords, crypto wallets, cloud credentials, GitHub Actions secrets, and service-account tokens. The malware exfiltrates the gathered data and keeps an open line to command-and-control infrastructure for further instructions.

An active malware process detects a revoked access token and deletes files from an infected user's directory.
Illustration: AI & Tech News

Installation scripts bypass sandboxes

Socket warns that this variant monitors specific stolen GitHub tokens. If a token gets revoked, the malware can trigger the deletion of an infected user directory under specific conditions. Security firms advise disabling that token monitor before revoking affected credentials.

Tensorlake operates a cloud-native platform for isolated AI agents and untrusted code. Socket points out that the malicious SDK installation script runs on developer machines or build servers outside sandbox protections. That process compromises the host environment before AI-generated code even runs.

Read nextPoeLLM malware infects exposed AI servers in cryptomining attacks

Quick removal limits exposure

The infected version of the npm package went live Thursday morning UTC. Socket reports that its engine flagged the malicious release just 11 minutes after publication. Both npm and Tensorlake pulled the compromised package quickly.

Tensorlake updated its software version to 0.5.145 to resolve the issue. Socket recommends rebuilding compromised systems from trusted sources before restoring access to secrets.

Newsletter

Get the best AI & tech news daily

A concise daily digest. Unsubscribe anytime.

We use your email only to send this newsletter.

Keep reading