As reported by The Hacker News, the npm package tensorlake (version 0.5.144) was compromised by the Shai-Hulud / ChainDrop supply chain campaign, delivering an obfuscated credential-stealing worm capable of persistence, remote code execution, and lateral propagation across a developer's publishing identity. The malicious release has since been pulled from npm, but the operational design of this malware warrants closer scrutiny because it deliberately resists the standard "rotate and move on" remediation playbook.

Threat Alert: As reported by The Hacker News, the npm package tensorlake (version 0.5.144) was compromised by the Shai-Hulud / ChainDrop supply chain campaign, delivering an obfuscated credential-stealing worm capable of persistence, remote code execution, and lateral propagation across a developer's publishing identity.

The most important detail in this incident is not the credential list — although it is broad, spanning npm and GitHub tokens, AWS secrets, HashiCorp Vault, Kubernetes, SSH keys, .env files, cryptocurrency wallets, and notably MCP configuration files for AI tooling such as Anthropic Claude, Cursor, Kiro, Windsurf, and Zed. The defining characteristic is the hostage token mechanism: a PowerShell watchdog that continuously polls api.github.com/user using the exfiltrated GitHub token and triggers a destructive handler the moment the victim revokes it. That is not opportunistic theft — it is engineered deterrence, designed to punish defenders for doing the right thing.

The risk surface for this campaign is not a single package. It is the entire CI/CD and developer-identity estate that touches any system where the package was installed.

Why the propagation model matters

Shai-Hulud is not a one-shot stealer. It enumerates packages tied to the victim's publishing identity, forges Sigstore provenance, and republishes compromised versions — effectively turning each infected maintainer into a new patient zero. Combined with planted GitHub Actions workflows and Ethereum-based C2 resolution (with GitHub as a fallback exfiltration channel), the campaign blends cryptocurrency infrastructure with the world's most widely trusted developer platform. That blend makes takedowns slow and attribution messy, because the C2 can be rotated on-chain faster than registry trust revocations can propagate.

For organizations, this reframes the impact calculus. The blast radius is not "which API key leaked" — it is "which of our maintainers, CI runners, or build agents executed a preinstall hook this week." Persistence means that removing the dependency does not close the hole; the host may still be reachable through attacker-supplied handlers or planted workflows. The presence of Invoke-Expression delivered destructive payload triggers means a compromised host should be treated as untrusted until rebuilt, not merely cleaned.

Who is most exposed

  • Teams consuming tensorlake@0.5.144 directly or transitively — check lockfiles immediately.
  • Any environment where npm installs run preinstall scripts without sandboxing — default npm behavior unless explicitly disabled.
  • AI-first engineering orgs whose developers store MCP server configuration locally — Shai-Hulud explicitly targets this emerging credential class.
  • Maintainers with broad npm publishing rights whose tokens could become the next propagation node.

Shield53 Recommendations

  • Treat installs as code execution, not dependency resolution. Disable lifecycle scripts by default (npm install --ignore-scripts) in CI and developer workstations unless a package is explicitly vetted. Enforce this via .npmrc policy and repository-level configuration.
  • Hunt for the indicators, not just the package. Search lockfiles and package-lock.json histories for tensorlake@0.5.144 and any version republished shortly after the compromise window. Inspect GitHub Actions workflows for unfamiliar entries planted by Dependabot/Copilot-impersonating commits.
  • Assume credential exposure is total. Rotate every secret that could have been readable by the executing process: npm publish tokens, GitHub PATs, AWS keys, Vault tokens, SSH keys, and any MCP server credentials. Do not assume the "hostage token" monitor failed to fire — it may already have run a destructive handler.
  • Rebuild, don't clean. Because persistence and remote code execution are in scope, redeploy affected CI runners and build containers from known-good images. Quarantine local developer machines that ran the install and inspect them offline before reconnecting.
  • Adopt provenance verification on both sides. Require Sigstore/SLSA provenance for consumed packages, and sign your own releases. Shai-Hulud forges provenance — so verification only helps if you also control the trust anchors, not just the badges.
  • Scope MCP credentials like cloud credentials. Treat MCP server configuration files as sensitive as .env. Use short-lived, scoped tokens and dedicated AI tooling identities rather than reusing developer principals.
  • Monitor the hostage-token behavior. Alert on anomalous calls to api.github.com/user from non-browser processes, and on PowerShell Invoke-Expression invocations originating from node or bun child processes.

This campaign is a useful inflection point. Supply chain attackers have moved past "steal the token and leave" into durable, retaliatory, self-propagating territory. Defenders who respond with token rotation alone will lose the second engagement. The correct posture is to assume the host is compromised until proven otherwise, and to treat developer-identity credentials as the most valuable and most aggressively hunted asset class in the modern stack.