Shai-Hulud is back for another round, this time hijacking the Tensorlake package, 12k weekly downloads
Breaking News: Shai-Hulud malware affecting “tensorlake” package version 0.5.144,
Overview
A malicious version of tensorlake (version 0.5.144) was published to npm with Shai-Hulud malware.
The malware also contains an Ethereum contract address, which is tied to a wallet containing 12.44$ worth of crypto currency.
Threat actors used new public keys that differ from other attacks. This may indicate an independent threat actor or a new group using the Shai-Hulud name and malicious code.
Who is affected
- Anyone who installed or ran tensorlake@0.5.144
Recommended Actions
- Do not revoke the stolen GitHub token before isolating the machine. Disconnect the host from the network and kill the gh-token-monitor persistence first (see IOCs). Otherwise, revocation triggers rm -rf ~/ (Windows: Remove-Item $env:USERPROFILE -Recurse -Force). Then rotate your keys.
- Treat every machine that installed it as fully compromised. Rotate all GitHub, npm, cloud, Vault, SSH and CI secrets reachable from it.
- Hunt for the IOCs below across GitHub (branches, workflow files, commits) and endpoints (persistence, network).
Threat Analysis
Inside the code we detected this Ethereum contract address – 0xb614155Fd88114d40549b259457Bcf921Df091B9 which maps to this wallet – 0x779f83aE56309682beDb04816c19d358c4B21040

When examining the wallet, we can see that the account currently holds 12.44$, and was created 16 days ago.

Additionally, we can see in GitHub that 5 repositories have been uploaded with stolen credentials following this recent attack.

Technical Analysis
The malware contains heavy obfuscation, with multiple decode functions and hash functions to extract its own strings to memory when running.

Public encryption keys are newly seen, and are not connected to any of the Shai-Hulud variants we’ve seen in the past.
- MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAsx7qQlP6BjB14dud92Hk
- MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAmSsAhtZtB2S7XBxe5Ofr


The malware’s revoke kill-switch string is the same one that was used in the TanStack attack back in May – IfYouRevokeThisTokenItWillWipeTheComputerOfTheOwner:

The malware contains infostealer logic, browser data stealing logic, crypto draining, cloud configuration stealing, environment variable stealing and many more.

Affected Packages
| Package name | Version | Registry |
| tensorlake | 0.5.144 | npm |
Conclusion
Shai-Hulud is yet again attacking AI and agentic frameworks, and in an ironic turn of events, a Sandbox for AI, the type of package that’s trying to prevent attacks and malwares like Shai-Hulud spreading in the wild.
Shai-Hulud variants keep breaking the assumption that we’ve learned our lesson and that our package managers and registries will be safe next week. Apparently, they won’t be.
The Shai-Hulud name, hardcoded in the malware’s source code, has outlived its TeamPCP origins. Group members were arrested in August. The name now works as a brand that copycats reuse.
Now, every Shai-Hulud reference becomes more of a statement, an almost poetic one, an ode to a group of threat actors that took over packages with billions of downloads all around the world.
IOCs
Domains / network
- iseekaigogo.com
- Ethereum contract 0xb614155Fd88114d40549b259457Bcf921Df091B9
Strings / markers
- WORMTAG = “tensrlake”
- WORM_PROFILE
- IfYouRevokeThisTokenItWillWipeTheComputerOfTheOwner
- thebeautifulmarchoftime
- Shai-Hulud: Here We Go Again
- Add Copilot workflow, chore: update dependencies
Files
- setup.mjs, .claude/setup.mjs, .vscode/setup.mjs, .claude/settings.json, .vscode/tasks.json
- Math_Symbol.js, math_init.js, opensearch_init.js, ai_init.js
- ~/.local/bin/gh-token-monitor.sh, ~/.config/gh-token-monitor/
- ~/.config/systemd/user/gh-token-monitor.service
- ~/Library/LaunchAgents/com.user.gh-token-monitor.plist
- Windows scheduled task gh-token-monitor; %LOCALAPPDATA%\gh-token-monitor
How OX Can Help
The above package and future variants of this malicious campaign are included in the OX security malware database.
OX customers using VibeSec trying to install one of the malicious packages will be blocked by the platform and an alternative safe package will be suggested to them.
OX customers pushing code with the malicious package as dependency will also be blocked by the OX platform pipeline scan.