Aikido

tensorlake NPM package compromised with Shai Hulud worm

Written by
Oliver Smith

On 8 October 2026 a threat actor published a compromised version of tensorlake to npm. The compromised version is 0.5.144 and contains a variant of the Shai-Hulud worm, which exfiltrates secrets from infected devices and attempts to self-replicate through connected supply chains. Tensorlake is a serverless sandbox for AI agents and its npm package has a reported lifetime install count of over 100,000. 

Tensorlake also distributes a package via PyPI and Cargo, but there is no sign the threat actor has been able to publish to either ecosystem at the time of writing. The malware contains slight variations from the last Shai-Hulud wave, so it is likely part of a novel compromise rather than ongoing reinfection. 

What the malware does

The malware is triggered via a preinstall script, which invokes node lib/setup.mjs. setup.mjs (25a0735d0db7dc40e5d45ce42d9c106067e6a66e184d967cfecfab17c3bcb5ef) is an obfuscated script that serves to drop Bun to an infected host and to execute lib/Math_Symbol.js (b50a00900399ba99fb6ce1fc151519cb99d44320ef2a631f2237e1aea0ad6fec) with the Bun runtime.

Math_Symbol.js contains an obfuscated Shai-Hulud payload. The malware sets a global WORMTAG marker before executing obfuscated code, specific to the infected tensorlake package. This marker indicates that the package is a novel compromise rather than an ongoing reinfection from a prior Shai-Hulud wave. 

The malware decrypts persistence and proliferation payloads and a dead-man's switch that wipes infected machines if an embedded GitHub token is revoked, consistent with prior Shai-Hulud waves. Also consistent with prior Shai-Hulud waves, the malware attempts to read and exfiltrate sensitive environment variables and local secrets. A full index of the data targeted by the malware is available at the end of this post. Any system or environment infected by the malware should be treated as fully compromised and any secrets or credentials it contained should be rotated as a critical priority.

The malware contains the hardcoded C2 address iseekaigogo[.]com, but also contains a blockchain dead-drop mechanism to resolve an alternate C2. The malware calls a read function on the threat actor-controlled Ethereum contract

0xb614155Fd88114d40549b259457Bcf921Df091B9 through eth.llamarpc.com, rpc.ankr.com and ethereum.publicnode.com to retrieve an alternative C2/exfiltration domain. The most recent update to the contract, made on 21 September from the wallet 0x779f83aE56309682beDb04816c19d358c4B21040, sets this value to the same hardcoded C2 address, iseekaigogo[.]com.

The malware differs from prior Shai-Hulud waves by attempting to read more sensitive data from web browser stores. The malware attempts to read data from hardcoded file paths related to 14 cryptocurrency browser extensions. The malware attempts to exfiltrate extension IndexedDB and LevelDB files. The malware also sources a remote HackBrowserData binary appropriate for the infected system from the C2 address and invokes it to attempt to obtain additional credentials from browser stores. These changes potentially reflect an operator more focussed on quickly monetising infected developer endpoints than on proliferating through the supply chain.

Tracing the infection

The malware originated from the tensorlake GitHub repository. On 7 October 2026, the threat actor made verified commits under the identity of a maintainer. The malware was introduced in commit 41b38f0 via direct file upload, after which the threat actor attempted to bump versions and trigger publishing. The repository was compromised for approximately 20 hours before the threat actor was able to trigger the npm publish. 

How Aikido detects this

If you are an Aikido user, check your central feed and filter on malware issues. This will surface as a 100/100 critical issue. Aikido rescans nightly, but we recommend triggering a manual rescan now.

If you are not yet an Aikido user, you can create an account and connect your repos. Our malware coverage is included in the free plan, no credit card required.

For broader coverage across your whole team, Aikido's Device Protection gives you visibility and control over the software packages installed on your team's devices. It covers browser extensions, code libraries, IDE plugins, and build dependencies, all in one place. Stop malware before it gets installed.

For future protection, consider Aikido Safe Chain (open source). Safe Chain sits in your existing workflow, intercepting npm, npx, yarn, pnpm, and pnpx commands and checking packages against Aikido Intel before install.

Indicators of compromise

NPM packages:

  • tensorlake 0.5.144

C2 domain:

  • iseekaigogo[.]com

Files:

  • lib/setup.mjs
    • 25a0735d0db7dc40e5d45ce42d9c106067e6a66e184d967cfecfab17c3bcb5ef
  • lib/Math_Symbol.js
    • b50a00900399ba99fb6ce1fc151519cb99d44320ef2a631f2237e1aea0ad6fec

Other:

  • Threat actor Ethereum transaction:
    • ‍0xb614155Fd88114d40549b259457Bcf921Df091B9
  • Threat actor Ethereum wallet:
    • 0x779f83aE56309682beDb04816c19d358c4B21040

Targeted variables and files

‍

Environment variables:

APPVEYOR
AWS_ACCESS_KEY_ID
AWS_CONFIG_FILE
AWS_CONTAINER_CREDENTIALS_FULL_URI
AWS_CONTAINER_CREDENTIALS_RELATIVE_URI
AWS_PROFILE
AWS_REGION
AWS_ROLE_ARN
AWS_SECRET_ACCESS_KEY
AWS_WEB_IDENTITY_TOKEN_FILE
bamboo_agentId
BITBUCKET_BUILD_NUMBER
BITRISE_IO
BUDDY_WORKSPACE_ID
BUILD_BUILDURI
BUILDKITE
CF_BUILD_ID
CF_PAGES
CI
CI_NAME
CIRCLECI
CIRRUS_CI
CODEBUILD_BUILD_ID
DISTELLI_APPNAME
DRONE
GITHUB_ACTIONS
GITLAB_CI
JB_SPACE_EXECUTION_NUMBER
JENKINS_URL
KUBECONFIG
KUBERNETES_SERVICE_HOST
NETLIFY
NOW_GITHUB_DEPLOYMENT
SAILCI
SCREWDRIVER
SEMAPHORE
SHIPPABLE
TEAMCITY_VERSION
TRAVIS
VAULT_ADDR
VAULT_API_TOKEN
VAULT_AUTH_TOKEN
VAULT_AWS_ROLE
VAULT_TOKEN
VAULT_TOKEN_FILE
VAULT_TOKEN_PATH
VELA
VERCEL
WERCKER_MAIN_PIPELINE_STARTED
WS_SHARED_CREDENTIALS_FILE

Credential file paths:

~/.ansible
~/.azure
~/.cert/nm-openvpn
~/.config/atomic/Local Storage/leveldb
~/.config/discord/Local Storage/leveldb
~/.config/Element/Local Storage
~/.config/Exodus/exodus.wallet
~/.config/helm
~/.config/kwalletd
~/.config/Ledger Live
~/.config/remmina
~/.config/Signal
~/.config/telegram-desktop
~/.docker
~/.electrum-ltc/wallets
~/.electrum/wallets
/etc/openvpn
/etc/ssh
~/.ethereum/keystore
~/.kde4/share/apps/kwallet
~/.kde/share/apps/kwallet
~/.local/share/keyrings
~/.local/share/TelegramDesktop/tdata
~/.monero
~/.pki/nssdb
~/.remmina
~/.ssh
/var/lib/docker/containers
~/.foundry/keystores
~/.brownie/accounts
~/.config/github-copilot
~/.gnupg/private-keys-v1.d
~/.config/gcloud/legacy_credentials
~/.volta/tools/image/node
~/.kube/cache/discovery
~/.kube/http-cache
~/.near-credentials
~/.keplr
~/.config/keplr
~/.bitcoin/wallets
~/.nethermind/keystore
~/.local/share/io.parity.ethereum/keys
~/.config/exodus/exodus.wallet
~/.local/share/gopass/stores
/etc/ssl/private
/etc/letsencrypt/live
~/.mozilla/firefox
~/.config/google-chrome
~/.config/chromium
~/.config/BraveSoftware/Brave-Browser
~/.config/microsoft-edge
~/.config/opera
~/.config/vivaldi
/etc/ssl/cert.pem
~/.aws/credentials
~/.aws/config
~/.kube/config
~/.vault-token
/home/runner/.vault-token
/vault/token
/var/run/secrets/vault-token
/var/run/secrets/vault/token
/run/secrets/vault_token
/run/secrets/VAULT_TOKEN
~/.vault/token
/etc/vault/token

Browser extensions:

nkbihfbeogaeaoehlefnkodbefgpgknn  MetaMask
bfnaelmomeimhlpmgjnjophhpkkoljpa  Phantom
hnfanknocfeofbddgcijnmhnfnkdnaad  Coinbase Wallet extension
acmacodkjbdgmoleebolmdjonilkdbch  Rabby Wallet
egjidjbpglichdcondbcbdnbeeppgdph  Trust Wallet
ibnejdfjmmkpcnlpebklmnkoeoihofec  TronLink
fnjhmkhhmkbjkkabndcnnogagogbneec  Ronin Wallet
bhhhlbepdkbapadjdnnojkbgioiodbic  Solflare Wallet
dmkamcknogkgcdfhhbddcghachkejeap  Keplr
aholpfdialjgjfhomihkjbmgjidlcdno  Exodus Web3 Wallet
mcohilncbfahbmgdjkbpemcciiolgcge  OKX Wallet
opfgelmcmbiajamepnmloijbpoleiama  Rainbow
ppbibelpcjmhbdihakflkdcoccbgbkpo  UniSat Wallet
lgmpcpglpngdoalbgeoldeajfclnhafa  SafePal Extension Wallet

‍

Share:

https://www.aikido.dev/blog/tensorlake-npm-package-compromised

Scan for malware

Start for Free
4.7/5
Tired of false positives?

Try Aikido like 100k others.
Start Now
Get a personalized walkthrough

Trusted by 100k+ teams

Book Now
Scan your app for IDORs and real attack paths

Trusted by 100k+ teams

Start Scanning
See how AI pentests your app

Trusted by 100k+ teams

Start Testing

Get secure today,
quickly and for free.

Secure your code, cloud, and runtime in one central system.
Connect a repo to discover what the reasoning agents find in your codebase.

No credit card required | Scan results in 32 seconds.
Trusted by 150k+ orgs