Socket says the malicious tensorlake@0.5.144 npm release plants a token monitor that wipes the home directory if you revoke the stolen GitHub token first.
Anyone who installed tensorlake@0.5.144 from npm should not start by revoking their GitHub token. According to Socket, the malware installs a monitor that polls the GitHub API with the stolen token and, when the token stops working, runs an attacker-supplied handler. Socket says the code carries the string "IfYouRevokeThisTokenItWillWipeTheComputerOfTheOwner", previously seen in earlier Shai-Hulud waves, and that revoking the token while the monitor runs triggers a wipe of the home directory. The safe order is to remove the monitor first, then rotate credentials.
What happened
Version 0.5.144 of the tensorlake npm SDK was published on 8 October 2026 at 01:12:07 UTC. Socket flagged it about 11 minutes later. Six tensorlake-native-*@0.5.144 platform packages came out of the same release run. Endor Labs found only a native binary in them, with no install script and no payload, but advises treating them as part of the affected release. Endor and The Hacker News report that 0.5.144 has been removed from npm. No source gives a takedown time. Clean versions are everything before 0.5.144; Endor suggests pinning 0.5.143.
No CVE has been assigned. Tensorlake also publishes on PyPI and Cargo, and Aikido saw no compromise there. No source we read carries a statement from Tensorlake.
Why it matters
Socket puts the package at about 12,000 weekly downloads and over 1,000 GitHub stars; it stresses that the figure is overall usage, not downloads of the malicious version or confirmed infections. It is an SDK for agent sandboxes and cloud services, so installs are likely to sit on developer laptops and CI runners holding npm, cloud and GitHub credentials. The payload targets those credentials, plus AI tool configuration (.claude, .cursor, .kiro, Windsurf, Zed). Socket files it under "ChainDrop / Shai-Hulud" and says the hook and payload filenames match the August compromises of keyv, cacheable and related npm packages; The Hacker News draws the same link to Keyv and Cacheable. Aikido calls it consistent with prior Shai-Hulud waves, but its WORMTAG marker points to a novel compromise rather than a reinfection. Aikido also reports over 100,000 lifetime installs of the package. ThreatFrontier covered an earlier wave in Mini Shai-Hulud.
For victims the cost is double. Theft of cloud and publishing credentials is the usual damage, but a wrong response to the theft could destroy local data, including unpushed work (we covered a similar credential-stealing package worm on 2 October).
Technical details
- Access. Aikido reports verified commits under a maintainer's identity, with the malware added by direct file upload in commit 41b38f0, and says the repository was compromised for about 20 hours before the npm publish was triggered. Endor Labs dates the first malicious commit (e90c47bbb2) to 7 October 01:20 UTC, roughly 24 hours before the publish; The Hacker News attributes the same time to StepSecurity. Endor says 0.5.144 shipped through the project's normal GitHub Actions pipeline with valid build provenance, the same trust gap discussed in our trusted-publishing piece above. Endor calls a compromised maintainer account the most likely root cause. That is inference, not confirmed.
- Execution. A preinstall hook runs node lib/setup.mjs, which fetches the Bun runtime and runs the obfuscated lib/Math_Symbol.js (Aikido).
- Theft. npm and GitHub tokens, AWS/GCP/Azure credentials, Vault and Kubernetes tokens, SSH keys, .env files, crypto wallets, browser stores and AI tool configs. Aikido adds that the variant fetches a HackBrowserData binary and reads paths for 14 crypto-wallet browser extensions.
- Exfiltration. A hardcoded HTTPS endpoint (Aikido, The Hacker News), an Ethereum smart-contract dead-drop for alternate command servers, and a GitHub public-repository fallback. Socket says the payload has no hardcoded command-and-control domain, while Aikido, The Hacker News and Endor name iseekaigogo[.]com (Endor lists it as disposable and rotated on-chain), so the sources disagree. Indicators are in the linked write-ups.
- Spread. Socket says the worm enumerates the victim's npm packages, builds Sigstore provenance and republishes infected versions; Endor Labs likewise says it republishes itself into other packages the victim controls. Socket also cites strings suggesting fake Copilot/Dependabot workflows, which is its inference from strings. StepSecurity's Ashish Kurmi, quoted by The Hacker News, found that the malware edits .claude/settings.json and .vscode/tasks.json in reachable repositories.
- Monitor. Socket: Linux uses the systemd user service gh-token-monitor.service with files under ~/.config/gh-token-monitor/; macOS uses ~/Library/LaunchAgents/com.user.gh-token-monitor.plist; Windows uses an ONLOGON scheduled task running monitor.ps1 (path not given). The handler runs through Invoke-Expression.
What defenders should do
Remove the monitor before you revoke anything (per Socket).
- Block tensorlake@0.5.144 and the tensorlake-native-*@0.5.144 packages in manifests and lockfiles. Find every machine and CI run that installed them.
- On those hosts, remove the monitor before anything else. Linux: run
systemctl --user disable --now gh-token-monitor.serviceand delete the directory. macOS: unload and delete the launch agent plist. Windows: delete the scheduled task. Check for all three persistence types. - Then revoke and rotate GitHub, npm, cloud, Vault, Kubernetes and SSH credentials. Back up unpushed work first if you cannot confirm the monitor is gone.
- Review GitHub and npm account activity, look for unexpected package publishes, new public repositories and new Actions workflows, and check .claude/settings.json and .vscode/tasks.json in your repos.
- Rebuild affected hosts from trusted images. Consider
--ignore-scriptsfor installs.
What is still unclear
- The wipe is described from code, not observed. Two research firms describe it from their own analysis: Socket says it wipes the home directory, Aikido says it wipes "infected machines"; The Hacker News relays Socket. The Endor Labs page does not mention a wipe, revocation or the monitor. No source reports a wipe that actually occurred.
- The Windows monitor location, the exact takedown time and the six native package names are not given.
- The root cause is unconfirmed, and Tensorlake has made no public statement in the sources.
- Socket says there is no hardcoded command server; Aikido, The Hacker News and Endor name one.