Security researchers at Socket and SafeDep reported Thursday that they had detected Shai-Hulud infection in version 0.5.144 of Tensorlake’s npm SDK. The malicious release shares code and techniques with the ChainDrop variant used in August to compromise npm dependencies including keyv and flat-cache. It is designed to steal crypto wallets, browser passwords, GitHub Actions secrets, cloud credentials and service-account tokens, then exfiltrate them and await further instructions from its command-and-control infrastructure.
The escape from sandboxing is the sharp edge. Tensorlake is a cloud-native platform for running isolated AI agents, but its SDK’s installation script can execute on the developer’s machine or build server, outside the sandbox protections. Worse, this variant monitors stolen GitHub tokens and, if one is revoked, can trigger deletion of the infected user’s home directory under specific conditions. Socket recommends rebuilding compromised systems from a trusted source before restoring access to secrets, and disabling the malicious token monitor before revoking affected credentials. Npm removed the infected version within the hour, and Tensorlake has published a clean 0.5.145.