tensorlake 0.5.143 -> 0.5.144lib/Math_Symbol.jsVersion 0.5.144 of the tensorlake npm package carried a credential-stealing worm. The package is the JavaScript SDK for Tensorlake, an AI agent infrastructure company.
Socket and Aikido both describe the release. It runs its payload during install, so a project that never imports the SDK still runs the malware.
What happened
On 8 October 2026 at 01:12:07 UTC, a new tensorlake release, version 0.5.144, went to npm with a hidden install hook. Socket flagged it at 01:23:10 UTC, about 11 minutes later.
Aikido traced the code to the Tensorlake GitHub repository. Aikido reports that on 7 October 2026 the actor made verified commits under a maintainer's identity. The malicious code came in through commit 41b38f0 as a direct file upload. The actor then attempted version bumps and triggered publishing. Aikido reports that the repository was compromised for about 20 hours before the npm release.
The package manifest has a preinstall hook that runs node lib/setup.mjs. That file is an obfuscated loader. It drops the Bun runtime and uses it to run lib/Math_Symbol.js. Both companies identify Math_Symbol.js as an obfuscated Shai-Hulud worm.
Socket lists the data the payload collects. The list includes npm tokens, GitHub tokens, AWS credentials, Vault instances, Kubernetes service-account tokens and kubeconfigs, SSH keys and .env files. It also covers crypto wallets, messaging app data and configuration files for AI development tools. Aikido adds that it drops a HackBrowserData binary to take cookies and saved credentials from browsers. Aikido notes that this browser theft is new compared with earlier waves.
The worm spreads through the victim's own packages. Socket reports that it lists the packages tied to the victim's publishing identity, builds Sigstore provenance and republishes poisoned versions. Socket also reports that it plants a fake Copilot or Dependabot GitHub Actions workflow.
The malware has no fixed server address in its code. Socket reports that it reads its endpoint from an Ethereum contract through about 30 public RPC endpoints, with a GitHub fallback. Aikido reports that it reads the most recent transaction of an Ethereum wallet and takes the server domain from that transaction's input data.
The two sources describe the token trap in different words. Socket reports a Windows PowerShell monitor, started by an ONLOGON scheduled task, that polls api.github.com/user with the stolen GitHub token. If the token is revoked, the monitor runs an attacker-supplied handler through Invoke-Expression. The code holds the string IfYouRevokeThisTokenItWillWipeTheComputerOfTheOwner. Aikido states that the malware wipes infected machines if the embedded GitHub token is revoked.
Socket links this release to the August 2026 ChainDrop and Shai-Hulud attack on keyv, cacheable and related packages. That wave used the same setup.mjs and Math_Symbol.js layout. Aikido reports that the payload sets a global WORMTAG marker, which marks a new compromise and not a reinfection.
Socket gives the package about 12,000 weekly downloads. Aikido gives a lifetime install count of over 100,000. Neither figure counts installs of the bad version alone.
Affected versions
Only tensorlake 0.5.144 on npm is named as malicious.
tensorlake0.5.144: malicious. Published 8 October 2026 at 01:12:07 UTC.- The npm registry lists 0.5.143 as the
latestversion. - Tensorlake also ships through PyPI and Cargo. Aikido reports no sign that the actor published to either one.
The worm republishes packages that belong to each victim. If a developer or CI system installed 0.5.144 and held npm publish rights, check that account's packages too.
Indicators of compromise
Socket and Aikido publish the same two file hashes. Aikido adds the server domain and the Ethereum wallet.
- Package:
tensorlake@0.5.144 lib/setup.mjsSHA-256:25a0735d0db7dc40e5d45ce42d9c106067e6a66e184d967cfecfab17c3bcb5eflib/Math_Symbol.jsSHA-256:b50a00900399ba99fb6ce1fc151519cb99d44320ef2a631f2237e1aea0ad6fec- Server domain (Aikido):
iseekaigogo[.]com - Ethereum wallet (Aikido):
0xb614155Fd88114d40549b259457Bcf921Df091B9 - Install hook:
preinstallrunningnode lib/setup.mjs - String in the payload (Socket):
IfYouRevokeThisTokenItWillWipeTheComputerOfTheOwner - A scheduled task that runs at logon and a PowerShell process that polls
api.github.com/user(Socket) - An unexpected GitHub Actions workflow named for Copilot or Dependabot (Socket)
How to check
List the installed version of tensorlake in each project. These commands only read files. They do not install or run anything.
npm ls tensorlake --all
Then search your lockfiles for the bad version.
grep -rn --include=package-lock.json -A2 '"node_modules/tensorlake"' .
If a copy is present in node_modules, compare its loader hash with the value above.
shasum -a 256 node_modules/tensorlake/lib/setup.mjs
If the version is 0.5.144, or the hash matches, treat that machine as compromised. Also check build logs and CI caches for an install of 0.5.144 between 8 October 2026 and the date you pinned a clean version.
What to do now
- Block
tensorlake@0.5.144and pin your projects to a clean version. - Isolate any machine or CI runner where 0.5.144 was installed with install scripts on. Removing the package does not remove the implant.
- Look for persistence: logon scheduled tasks, PowerShell monitors and new GitHub Actions workflows.
- On Windows hosts, isolate the machine before you revoke its GitHub token. Both sources tie token revocation to a destructive action on the infected host.
- Rotate npm, GitHub, cloud, Vault, Kubernetes and SSH credentials from a clean machine.
- Audit npm and GitHub accounts for unexpected publishes, new workflows and repository changes.
- Rebuild affected environments from trusted sources. Restore secrets only after the rebuild.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 46 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED lib/Math_Symbol.js It now runs a command on its own when it is installed and reads saved passwords and access keys. It did not before.
Frequently asked questions
Which tensorlake version is malicious?
Version 0.5.144 of the tensorlake npm package, published on 8 October 2026 at 01:12:07 UTC. The npm registry lists 0.5.143 as the latest version.
Does the tensorlake malware run if I never import the SDK?
Yes. A preinstall hook runs node lib/setup.mjs during npm install. Installation alone starts the payload where install scripts are allowed.
Is the tensorlake Python package affected?
Aikido reports no sign that the actor published to PyPI or Cargo. Only the npm package version 0.5.144 is named as malicious.