> Shai-Hulud worm makes jump to AI infrastructure with Tensorlake compromise
[DATE: 08/10/2026 16:54]
[LANGUAGE: EN]
The credential-hijacking Shai-Hulud worm has struck again, this time burrowing its way into a popular AI agent platform SDK. Multiple security researchers reported Thursday that they had detected Shai-Hulud infection in a recent release of the npm package for version 0.5.144 of Tensorlake’s SDK. That package has somewhere in the neighborhood of 12,000 downloads per week, while its GitHub repository has more than a thousand stars, suggesting it’s quite popular and that the infection could pose a serious risk to anyone who installed the malicious version. Analysis of the malicious release suggests it shares code and techniques with the Shai-Hulud variant dubbed ChainDrop by researchers, which was used in August to compromise npm dependencies including keyv and flat-cache. Like other variants of Shai-Hulud, the worm is designed to steal credentials and self-propagate. This particular version, according to supply chain security firm SafeDep, is designed to steal everything from crypto wallets to browser passwords, GitHub Actions secrets, cloud credentials, service-account tokens, and whatever else it can get its hands on. It exfiltrates that data and keeps an open line to its C2 infrastructure to await further instructions. To make matters worse, this Shai-Hulud variant monitors certain stolen GitHub tokens and, if one is revoked, can trigger the deletion of the infected user's home directory under specific conditions, making removal tricky. Socket recommends rebuilding compromised systems from a trusted source before restoring access to secrets, while researchers warn that the malicious token monitor should be disabled before revoking affected credentials. Tensorlake, for those unfamiliar, is a cloud-native platform for running isolated AI agents and untrusted AI-authored code. The infected npm SDK is used to create and manage Tensorlake environments. Socket warns that the malicious SDK's installation script can execute on the developer's machine or build server, outside Tensorlake's sandbox protections, potentially compromising the host before any AI-generated code is run. “Teams may isolate an agent’s generated code while installing its SDK on a developer workstation, application server, or build runner with access to deployment credentials and other secrets,” Socket noted. “Code executed during that installation inherits the permissions of the installing process.” That may sound bad, but it’s worth noting the malicious version wasn’t up for long - according to security firm Socket, the infected version was published to npm earlier this morning, UTC, and was flagged by its engine 11 minutes after publication. Npm removed the version, and Tensorlake has pulled the package as well, updating the version to 0.5.145. Best check to be sure you haven't installed the malicious version if you're a Tensorlake user. ®