What happened
On 2026-10-08, version 0.5.144 of the tensorlake npm SDK shipped obfuscated malware (a Shai-Hulud/ChainDrop worm variant) via an npm provenance-attested release built from the project's own main branch after rogue commits on Oct 7. The worm steals GitHub/npm tokens, AWS credentials, Kubernetes/Vault secrets, SSH keys, browser data, crypto wallets, and AI-tool configs (Claude, Cursor, Kiro, Windsurf, Zed MCP files); drops HackBrowserData; establishes persistence; executes attacker-supplied remote code; injects itself into the victim's own packages and republishes them under the victim's publisher identity; and plants `.claude/settings.json`/`.vscode/tasks.json` backdoors. A 'hostage token' component polls api.github.com with the stolen GitHub token and, if it is revoked, triggers a destructive PowerShell routine (potentially `rm -rf ~`) — removal of the monitor service must precede token rotation.
Why it matters
This is the first confirmed Shai-Hulud jump into AI-agent infrastructure: the payload specifically exfiltrates MCP/config files for Claude Code, Cursor, Windsurf, and Zed, and plants agent-hook config so it re-executes when a developer opens the repo in an AI coding agent. Compromised AI-tool credentials plus self-republishing under the victim's npm identity convert victims into propagation vectors for downstream consumers, and the wipe switch makes naïve incident response destructive. This is materially distinct from the earlier subql/common incident already covered.
Attack vector
Supply-chain: rogue commits pushed to the upstream main branch under a maintainer's name on 2026-10-07; the release workflow published the malicious 0.5.144 to npm on 2026-10-08 with a valid Sigstore provenance attestation, so it looks legitimate. Preinstall hook launches an obfuscated Bun-based loader that drops the worm and HackBrowserData stealer, harvests secrets, and self-propagates.
Affected systems
tensorlake npm package 0.5.144 (last safe version 0.5.143); PyPI and Cargo distributions unaffected
Mitigation
Remove tensorlake 0.5.144, pin to 0.5.143 or a clean version; before rotating tokens, remove the spawned persistence/gh-token-monitor service to avoid triggering the destructive dead-man's switch; rotate npm/GitHub/AWS/Vault/K8s/SSH credentials; audit repos for injected .claude/settings.json and .vscode/tasks.json backdoors and republished malicious packages under your npm identity. References: The Hacker News and StepSecurity writeups.