A threat actor published a compromised version of the tensorlake npm package on October 8, carrying a variant of the Shai-Hulud worm that security firm Aikido describes as a novel compromise rather than an ongoing reinfection from prior waves.

The compromised version is 0.5.144; 0.5.143 is the last safe version. Tensorlake is a serverless sandbox for AI agents, and its npm package has a reported lifetime install count of over 100,000. The project also distributes via PyPI and Cargo; no signs of compromise in either ecosystem had been observed at the time of writing, according to analysis corroborated by SafeDep, Techzine and The Hacker News.

What the Malware Does

The payload is triggered by a preinstall script invoking node lib/setup.mjs, an obfuscated dropper that installs the Bun runtime and executes a second obfuscated file, lib/Math_Symbol.js, containing the worm proper. Consistent with earlier Shai-Hulud waves, the malware exfiltrates sensitive environment variables — CI/CD tokens, AWS credentials, Vault tokens — and harvests credential files from paths including ~/.ssh, ~/.aws, ~/.gnupg, Ethereum keystores, Electrum and Monero wallets, and Foundry and Brownie account stores.

It also retains the worm family's most destructive feature: a dead-man's switch that wipes infected machines if an embedded GitHub token is revoked — a deterrent against takedown attempts.

The New Capability: Wallet Extension Theft

The notable evolution in this variant is a focus on cryptocurrency browser extensions. Aikido's analysis found the malware reads IndexedDB and LevelDB files from hardcoded paths for 14 wallet extensions, including MetaMask, Phantom, Coinbase Wallet, Rabby, Trust Wallet, TronLink, Ronin, Solflare, Keplr, Exodus Web3, OKX Wallet, Rainbow, UniSat and SafePal. The malware additionally downloads the HackBrowserData binary from its command-and-control server to extract further credentials from browser stores.

Aikido's assessment: the changes suggest an operator more focused on quickly monetizing infected developer endpoints than on propagating through the supply chain — although the worm retains its self-replication capability.

Blockchain Dead-Drop C2

Beyond the hardcoded C2 domain iseekaigogo[.]com, the malware contains a fallback mechanism familiar from this family: it reads an Ethereum contract controlled by the threat actor (0xb614155Fd88114d40549b259457Bcf921Df091B9) through public RPC endpoints to resolve an alternate exfiltration domain. The most recent contract update, made September 21 from wallet 0x779f83aE56309682beDb04816c19d358c4B21040, pointed back to the same hardcoded domain.

How the Repository Was Compromised

The infection path traces to the tensorlake GitHub repository. On October 7, the threat actor made verified commits under the identity of a maintainer, introducing the payload in commit 41b38f0 via direct file upload through the GitHub web interface, then attempted to bump versions and trigger the npm publish. The repository sat compromised for approximately 20 hours before the actor succeeded in publishing to npm.

Response Guidance

Any system that installed the compromised version should be treated as fully compromised. All secrets and credentials on infected machines — API keys, cloud credentials, wallet data, SSH keys — should be rotated as a critical priority. Organizations should check dependency manifests for [email protected] and review the indicators of compromise published by Aikido.

TrustGrade tracks the security posture of platforms and protocols in digital assets. Verified trust data: trustgrade.ai.