Shai-Hulud Malware Hits Tensorlake npm Package Again
The Shai-Hulud malware has resurfaced, this time inside the tensorlake npm package. A malicious release, version 0.5.144, was published to a package with about 12,000 weekly downloads, making this another supply chain attack on a widely used developer tool. The irony is hard to miss: tensorlake is an AI sandbox package, built to prevent exactly this kind of attack.

Same Name, Different Hands

The attackers used new public keys, different from those seen in earlier Shai-Hulud incidents. That points to a new, independent actor or group now running the Shai-Hulud name and code. The payload is heavily obfuscated, using multiple decode and hash functions to pull strings into memory only at execution.

It also carries infostealer logic that can take browser data, crypto, cloud configurations and environment variables. The code embeds an Ethereum contract address, 0xb614155Fd88114d40549b259457Bcf921Df091B9, tied to a wallet holding just $12.44. The revoke kill-switch string, IfYouRevokeThisTokenItWillWipeTheComputerOfTheOwner, is identical to the one used in the TanStack attack in May, which gives defenders a consistent signature to look for.

The Shai-Hulud name is hardcoded in the malware’s source, and it has outlived its TeamPCP origins, whose group members were arrested in August. It now works as a brand that copycat groups reuse, and it keeps targeting AI and agentic frameworks.

Kill the Persistence Before Touching Any Token

Anyone who installed or ran [email protected] should treat every machine that installed it as fully compromised.

Package name Version Registry
tensorlake 0.5.144 npm

The order of your response matters. Revoking GitHub tokens too early triggers a destructive command: rm -rf ~/, or Remove-Item $env:USERPROFILE -Recurse -Force on Windows.

  1. Disconnect the host from the network immediately.
  2. Kill the gh-token-monitor persistence first, before revoking anything.
  3. Rotate all GitHub, npm, cloud, Vault, SSH and CI secrets.
  4. Hunt for Indicators of Compromise (IOCs) across GitHub and endpoints.

On the prevention side, malicious dependency vetting services such as OX Security’s VibeSec aim to block packages like this before they land. The OX platform also blocks code with malicious dependencies during pipeline scans.

Hashlytics Take

The $12.44 wallet will get the jokes, but it is the wrong number to focus on. The real danger is the wipe command sitting behind the most instinctive response, since revoking a stolen token is what most incident playbooks tell you to do first. And with new keys in the code and the original group’s members arrested, the Shai-Hulud label no longer says who is behind an attack, so older indicators and timelines can’t be assumed to carry over. Anyone pulling AI packages straight from npm should treat a fresh release of even a trusted package as unvetted until proven otherwise.

Follow Hashlytics on Bluesky, Facebook, LinkedIn , Telegram and X to Get Instant Updates