On 8 October 2026 a threat actor published a compromised version of tensorlake to npm. The compromised version is 0.5.144 and contains a variant of the Shai-Hulud worm, which exfiltrates secrets from infected devices and attempts to self-replicate through connected supply chains. Tensorlake is a serverless sandbox for AI agents and its npm package has a reported lifetime install count of over 100,000.
Tensorlake also distributes a package via PyPI and Cargo, but there is no sign the threat actor has been able to publish to either ecosystem at the time of writing. The malware contains slight variations from the last Shai-Hulud wave, so it is likely part of a novel compromise rather than ongoing reinfection.
What the malware does
The malware is triggered via a preinstall script, which invokes node lib/setup.mjs. setup.mjs (25a0735d0db7dc40e5d45ce42d9c106067e6a66e184d967cfecfab17c3bcb5ef) is an obfuscated script that serves to drop Bun to an infected host and to execute lib/Math_Symbol.js (b50a00900399ba99fb6ce1fc151519cb99d44320ef2a631f2237e1aea0ad6fec) with the Bun runtime.
Math_Symbol.js contains an obfuscated Shai-Hulud payload. The malware sets a global WORMTAG marker before executing obfuscated code, specific to the infected tensorlake package. This marker indicates that the package is a novel compromise rather than an ongoing reinfection from a prior Shai-Hulud wave.
The malware decrypts persistence and proliferation payloads and a dead-man's switch that wipes infected machines if an embedded GitHub token is revoked, consistent with prior Shai-Hulud waves. Also consistent with prior Shai-Hulud waves, the malware attempts to read and exfiltrate sensitive environment variables and local secrets. A full index of the data targeted by the malware is available at the end of this post. Any system or environment infected by the malware should be treated as fully compromised and any secrets or credentials it contained should be rotated as a critical priority.
The malware contains the hardcoded C2 address iseekaigogo[.]com, but also contains a blockchain dead-drop mechanism to resolve an alternate C2. The malware calls a read function on the threat actor-controlled Ethereum contract
0xb614155Fd88114d40549b259457Bcf921Df091B9 through eth.llamarpc.com, rpc.ankr.com and ethereum.publicnode.com to retrieve an alternative C2/exfiltration domain. The most recent update to the contract, made on 21 September from the wallet 0x779f83aE56309682beDb04816c19d358c4B21040, sets this value to the same hardcoded C2 address, iseekaigogo[.]com.
The malware differs from prior Shai-Hulud waves by attempting to read more sensitive data from web browser stores. The malware attempts to read data from hardcoded file paths related to 14 cryptocurrency browser extensions. The malware attempts to exfiltrate extension IndexedDB and LevelDB files. The malware also sources a remote HackBrowserData binary appropriate for the infected system from the C2 address and invokes it to attempt to obtain additional credentials from browser stores. These changes potentially reflect an operator more focussed on quickly monetising infected developer endpoints than on proliferating through the supply chain.
Tracing the infection
The malware originated from the tensorlake GitHub repository. On 7 October 2026, the threat actor made verified commits under the identity of a maintainer. The malware was introduced in commit 41b38f0 via direct file upload, after which the threat actor attempted to bump versions and trigger publishing. The repository was compromised for approximately 20 hours before the threat actor was able to trigger the npm publish.
How Aikido detects this
If you are an Aikido user, check your central feed and filter on malware issues. This will surface as a 100/100 critical issue. Aikido rescans nightly, but we recommend triggering a manual rescan now.
If you are not yet an Aikido user, you can create an account and connect your repos. Our malware coverage is included in the free plan, no credit card required.
For broader coverage across your whole team, Aikido's Device Protection gives you visibility and control over the software packages installed on your team's devices. It covers browser extensions, code libraries, IDE plugins, and build dependencies, all in one place. Stop malware before it gets installed.
For future protection, consider Aikido Safe Chain (open source). Safe Chain sits in your existing workflow, intercepting npm, npx, yarn, pnpm, and pnpx commands and checking packages against Aikido Intel before install.
Indicators of compromise
NPM packages:
- tensorlake 0.5.144
C2 domain:
iseekaigogo[.]com
Files:
lib/setup.mjs25a0735d0db7dc40e5d45ce42d9c106067e6a66e184d967cfecfab17c3bcb5ef
lib/Math_Symbol.jsb50a00900399ba99fb6ce1fc151519cb99d44320ef2a631f2237e1aea0ad6fec
Other:
- Threat actor Ethereum transaction:
-
0xb614155Fd88114d40549b259457Bcf921Df091B9
-
- Threat actor Ethereum wallet:
0x779f83aE56309682beDb04816c19d358c4B21040
Targeted variables and files
Environment variables:
APPVEYOR
AWS_ACCESS_KEY_ID
AWS_CONFIG_FILE
AWS_CONTAINER_CREDENTIALS_FULL_URI
AWS_CONTAINER_CREDENTIALS_RELATIVE_URI
AWS_PROFILE
AWS_REGION
AWS_ROLE_ARN
AWS_SECRET_ACCESS_KEY
AWS_WEB_IDENTITY_TOKEN_FILE
bamboo_agentId
BITBUCKET_BUILD_NUMBER
BITRISE_IO
BUDDY_WORKSPACE_ID
BUILD_BUILDURI
BUILDKITE
CF_BUILD_ID
CF_PAGES
CI
CI_NAME
CIRCLECI
CIRRUS_CI
CODEBUILD_BUILD_ID
DISTELLI_APPNAME
DRONE
GITHUB_ACTIONS
GITLAB_CI
JB_SPACE_EXECUTION_NUMBER
JENKINS_URL
KUBECONFIG
KUBERNETES_SERVICE_HOST
NETLIFY
NOW_GITHUB_DEPLOYMENT
SAILCI
SCREWDRIVER
SEMAPHORE
SHIPPABLE
TEAMCITY_VERSION
TRAVIS
VAULT_ADDR
VAULT_API_TOKEN
VAULT_AUTH_TOKEN
VAULT_AWS_ROLE
VAULT_TOKEN
VAULT_TOKEN_FILE
VAULT_TOKEN_PATH
VELA
VERCEL
WERCKER_MAIN_PIPELINE_STARTED
WS_SHARED_CREDENTIALS_FILECredential file paths:
~/.ansible
~/.azure
~/.cert/nm-openvpn
~/.config/atomic/Local Storage/leveldb
~/.config/discord/Local Storage/leveldb
~/.config/Element/Local Storage
~/.config/Exodus/exodus.wallet
~/.config/helm
~/.config/kwalletd
~/.config/Ledger Live
~/.config/remmina
~/.config/Signal
~/.config/telegram-desktop
~/.docker
~/.electrum-ltc/wallets
~/.electrum/wallets
/etc/openvpn
/etc/ssh
~/.ethereum/keystore
~/.kde4/share/apps/kwallet
~/.kde/share/apps/kwallet
~/.local/share/keyrings
~/.local/share/TelegramDesktop/tdata
~/.monero
~/.pki/nssdb
~/.remmina
~/.ssh
/var/lib/docker/containers
~/.foundry/keystores
~/.brownie/accounts
~/.config/github-copilot
~/.gnupg/private-keys-v1.d
~/.config/gcloud/legacy_credentials
~/.volta/tools/image/node
~/.kube/cache/discovery
~/.kube/http-cache
~/.near-credentials
~/.keplr
~/.config/keplr
~/.bitcoin/wallets
~/.nethermind/keystore
~/.local/share/io.parity.ethereum/keys
~/.config/exodus/exodus.wallet
~/.local/share/gopass/stores
/etc/ssl/private
/etc/letsencrypt/live
~/.mozilla/firefox
~/.config/google-chrome
~/.config/chromium
~/.config/BraveSoftware/Brave-Browser
~/.config/microsoft-edge
~/.config/opera
~/.config/vivaldi
/etc/ssl/cert.pem
~/.aws/credentials
~/.aws/config
~/.kube/config
~/.vault-token
/home/runner/.vault-token
/vault/token
/var/run/secrets/vault-token
/var/run/secrets/vault/token
/run/secrets/vault_token
/run/secrets/VAULT_TOKEN
~/.vault/token
/etc/vault/tokenBrowser extensions:
nkbihfbeogaeaoehlefnkodbefgpgknn MetaMask
bfnaelmomeimhlpmgjnjophhpkkoljpa Phantom
hnfanknocfeofbddgcijnmhnfnkdnaad Coinbase Wallet extension
acmacodkjbdgmoleebolmdjonilkdbch Rabby Wallet
egjidjbpglichdcondbcbdnbeeppgdph Trust Wallet
ibnejdfjmmkpcnlpebklmnkoeoihofec TronLink
fnjhmkhhmkbjkkabndcnnogagogbneec Ronin Wallet
bhhhlbepdkbapadjdnnojkbgioiodbic Solflare Wallet
dmkamcknogkgcdfhhbddcghachkejeap Keplr
aholpfdialjgjfhomihkjbmgjidlcdno Exodus Web3 Wallet
mcohilncbfahbmgdjkbpemcciiolgcge OKX Wallet
opfgelmcmbiajamepnmloijbpoleiama Rainbow
ppbibelpcjmhbdihakflkdcoccbgbkpo UniSat Wallet
lgmpcpglpngdoalbgeoldeajfclnhafa SafePal Extension Wallet