MediumNews
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
- Published
- Record updated
Summary
Socket detected a compromised release, version 0.5.144, of the tensorlake npm SDK, which provides isolated sandboxes for running untrusted, LLM-generated code. The malicious version, published October 8, 2026, uses a preinstall hook ("node lib/setup.mjs") to launch an obfuscated credential-stealing and self-propagating payload, Math_Symbol.js, during installation. The payload harvests npm, GitHub, AWS, Vault, Kubernetes, SSH and AI development tool credentials, then republishes compromised packages.
Related items
- InfoStepSecurity Now Inventories AI Agent Skills in Your GitHub Repositories and on Developer Machines Similar attack · StepSecurity Blog
- LowCVE-2026-107288: Pydantic AI web fetch bypasses blocked_domains via hostname variantsSimilar attack · NVD/CVE Database
- LowOAuth grants pile up faster than you can review them. Here's how to keep up.Similar attack · BleepingComputer
- MediumTop MCP security resources — October 2026Similar attack · Adversa AI Blog
- MediumPoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining BotnetSimilar attack · The Hacker News