← Back to the feed

Malicious Tensorlake SDK release exposed AI developers’ credentials and files

The Register ·

Shai-Hulud credential-stealing malware was found in version 0.5.144 of Tensorlake’s npm SDK, which is used to create and manage environments for AI agents. The compromise matters because the SDK’s installation script could run on a developer’s machine or build server with access to sensitive credentials, beyond Tensorlake’s sandbox protections.

The infected package had around 12,000 downloads a week and was flagged by Socket 11 minutes after it was published; npm removed it and Tensorlake updated the SDK to version 0.5.145. Researchers say the malware can steal credentials including cloud secrets, GitHub tokens and browser passwords, then spread further. Under certain conditions, revoking a monitored GitHub token can trigger deletion of the affected user’s home directory.

  • Shai-Hulud was found in Tensorlake SDK version 0.5.144.
  • The package was flagged 11 minutes after publication and removed.
  • Researchers warn it could steal secrets from developer systems.

New here? Start with this

Tensorlake provides tools for developers building artificial intelligence systems. Its toolkit helps developers create and manage environments where AI agents run, and is shared through npm, an online service where developers download code components they use in their projects.

In October 2026, malicious code was discovered hidden in version 0.5.144 of Tensorlake's toolkit. The compromised package had been downloaded roughly 12,000 times per week, but security researchers flagged it just eleven minutes after release. npm removed the malicious version and Tensorlake quickly released a fixed update.

The threat matters because this toolkit runs with high privileges on developers' computers or company servers, giving the malware access to sensitive information such as cloud account logins, tokens for services like GitHub, and stored passwords. Researchers found the malware was designed to steal this information and spread to other systems, with scenarios potentially allowing deletion of files on affected machines.

Both sides, in good faith

The strongest fair case each way — we don't pick a winner.

The case for

This incident exposes critical gaps in package ecosystem security. Malware sat published and accessible for 11 minutes, during which thousands of developers could have downloaded it. Current mechanisms rely on post-facto detection rather than preventive controls—by then, developer machines may already be compromised. The ecosystem needs stronger vetting at publication time, mandatory code signing, stricter maintainer verification, and sandboxed execution of installation scripts to prevent supply chain attacks before they occur.

The case against

The security measures actually functioned as intended. Detection and response were swift—11 minutes is extraordinarily fast—and the patch was deployed immediately. Implementing prohibitively restrictive pre-publication vetting would create severe bottlenecks that slow legitimate development and innovation across thousands of projects. The practical approach is rapid detection and response, which this incident demonstrates works. Overengineering preventive barriers risks making the ecosystem less resilient and accessible without eliminating risk entirely.

AI Cybersecurity Technology

Read the full article at the source →

Originally published by The Register as “Shai-Hulud worm makes jump to AI infrastructure with Tensorlake compromise”.