“Shai-Hulud: Here We Go Again” – “tensorlake” npm Package Hit With Malware

Shai Hulud malware affecting tensorlake package
Share

Shai-Hulud is back for another round, this time hijacking the Tensorlake package, 12k weekly downloads

Breaking News: Shai-Hulud malware affecting “tensorlake” package version 0.5.144, 

Overview

A malicious version of tensorlake (version 0.5.144) was published to npm with Shai-Hulud malware.

The malware also contains an Ethereum contract address, which is tied to a wallet containing 12.44$ worth of crypto currency. 

Threat actors used new public keys that differ from other attacks. This may indicate an independent threat actor or a new group using the Shai-Hulud name and malicious code.

Who is affected

  • Anyone who installed or ran tensorlake@0.5.144
  1. Do not revoke the stolen GitHub token before isolating the machine. Disconnect the host from the network and kill the gh-token-monitor persistence first (see IOCs). Otherwise, revocation triggers rm -rf ~/ (Windows: Remove-Item $env:USERPROFILE -Recurse -Force). Then rotate your keys.
  2. Treat every machine that installed it as fully compromised. Rotate all GitHub, npm, cloud, Vault, SSH and CI secrets reachable from it.
  3. Hunt for the IOCs below across GitHub (branches, workflow files, commits) and endpoints (persistence, network).

Threat Analysis

Inside the code we detected this Ethereum contract address – 0xb614155Fd88114d40549b259457Bcf921Df091B9 which maps to this wallet – 0x779f83aE56309682beDb04816c19d358c4B21040

image

When examining the wallet, we can see that the account currently holds 12.44$, and was created 16 days ago.

image

Additionally, we can see in GitHub that 5 repositories have been uploaded with stolen credentials following this recent attack.

image

Technical Analysis

The malware contains heavy obfuscation, with multiple decode functions and hash functions to extract its own strings to memory when running.

image

Public encryption keys are newly seen, and are not connected to any of the Shai-Hulud variants we’ve seen in the past.

  • MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAsx7qQlP6BjB14dud92Hk
  • MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAmSsAhtZtB2S7XBxe5Ofr
image
image

The malware’s revoke kill-switch string is the same one that was used in the TanStack attack back in May – IfYouRevokeThisTokenItWillWipeTheComputerOfTheOwner:

image

The malware contains infostealer logic, browser data stealing logic, crypto draining, cloud configuration stealing, environment variable stealing and many more.

image

Affected Packages

Package nameVersionRegistry
tensorlake0.5.144npm

Conclusion

Shai-Hulud is yet again attacking AI and agentic frameworks, and in an ironic turn of events, a Sandbox for AI, the type of package that’s trying to prevent attacks and malwares like Shai-Hulud spreading in the wild.

Shai-Hulud variants keep breaking the assumption that we’ve learned our lesson and that our package managers and registries will be safe next week. Apparently, they won’t be.

The Shai-Hulud name, hardcoded in the malware’s source code, has outlived its TeamPCP origins. Group members were arrested in August. The name now works as a brand that copycats reuse.

Now, every Shai-Hulud reference becomes more of a statement, an almost poetic one, an ode to a group of threat actors that took over packages with billions of downloads all around the world.

IOCs

Domains / network

  • iseekaigogo.com 
  • Ethereum contract 0xb614155Fd88114d40549b259457Bcf921Df091B9

Strings / markers

  • WORMTAG = “tensrlake”
  • WORM_PROFILE
  • IfYouRevokeThisTokenItWillWipeTheComputerOfTheOwner
  • thebeautifulmarchoftime
  • Shai-Hulud: Here We Go Again
  • Add Copilot workflow, chore: update dependencies

Files

  • setup.mjs, .claude/setup.mjs, .vscode/setup.mjs, .claude/settings.json, .vscode/tasks.json
  • Math_Symbol.js, math_init.js, opensearch_init.js, ai_init.js
  • ~/.local/bin/gh-token-monitor.sh, ~/.config/gh-token-monitor/
  • ~/.config/systemd/user/gh-token-monitor.service
  • ~/Library/LaunchAgents/com.user.gh-token-monitor.plist
  • Windows scheduled task gh-token-monitor; %LOCALAPPDATA%\gh-token-monitor

How OX Can Help

Malicious dependency vetting

The above package and future variants of this malicious campaign are included in the OX security malware database. 

OX customers using VibeSec trying to install one of the malicious packages  will be blocked by the platform and an alternative safe package will be suggested to them. 

OX customers pushing code with the malicious package as dependency will also be blocked by the OX platform pipeline scan. 

Tags:

OX cloud 1

Active AI Defense. Complete Cloud Visibility.

Your agents hold identities you never issued. See what they touch, in real time.

Meet OX Cloud