Skip to content
MediumNews

TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack

Published
Record updated
View JSON

Summary

Socket detected a compromised release, version 0.5.144, of the tensorlake npm SDK, which provides isolated sandboxes for running untrusted, LLM-generated code. The malicious version, published October 8, 2026, uses a preinstall hook ("node lib/setup.mjs") to launch an obfuscated credential-stealing and self-propagating payload, Math_Symbol.js, during installation. The payload harvests npm, GitHub, AWS, Vault, Kubernetes, SSH and AI development tool credentials, then republishes compromised packages.