What Happened
Attackers published a compromised version of the tensorlake npm SDK. The Hacker News reports version 0.5.144 ran a preinstall hook which started an obfuscated loader and a credential-stealing worm. Socket and StepSecurity tie it to the ChainDrop and Shai-Hulud campaign first documented in August. A rogue commit landed on October 7 under a maintainer’s name. npm has removed the version.
The worm steals npm, GitHub, and AWS tokens, HashiCorp Vault and Kubernetes credentials, SSH keys, .env files, and wallets. It also reads configuration files for Claude, Cursor, Kiro, Windsurf, and Zed. It republishes infected packages with valid Sigstore provenance. It writes .claude/settings.json and .vscode/tasks.json into reachable repositories so it runs again when developers open them. A monitor checks whether the stolen GitHub token still works and runs an attacker handler if it is revoked.
Why This Matters for Canadian Organizations
Canadian software teams, banks, and public sector developers pull npm packages daily, and AI tooling pulls in new SDKs fast. One install on a build server hands an attacker cloud keys and the ability to publish under your name. A leak of customer data through stolen cloud credentials triggers PIPEDA breach reporting. Federally regulated institutions must treat the compromised dependency as an OSFI Guideline B-13 third-party risk.
What to Do
Search lockfiles and CI logs for tensorlake 0.5.144. If you find it, isolate the machine and back up what you need before revoking the GitHub token, because the hostage monitor is built to trigger a destructive routine. Then rotate every npm, GitHub, cloud, Vault, and Kubernetes credential the host held. Audit repositories for unexpected .claude/settings.json and .vscode/tasks.json files. Disable install scripts in CI where possible and pin dependency versions. Read more in our TechTalk coverage and daily briefs.






