Tensorlake npm attack delivers worm that steals dev credentials
A compromised Tensorlake SDK release introduced a self‑propagating worm that steals credentials and secrets from developers’ machines and CI environments.
Talk With Tech Newsroom
Updated 8 Oct 2026
The short version
The npm package tensorlake was compromised in a supply chain attack, delivering a credential‑stealing worm.
The malicious release 0.5.144 used a preinstall hook and an obfuscated loader to run a self‑propagating payload.
The worm targets credentials and secrets across local files, CI environments, Kubernetes, and Vault sources, and sets up persistence.
Users are advised to remove the malicious package and rotate their credentials immediately.
Quick read · 1 min
A compromised npm package called tensorlake carried a credential‑stealing worm as part of a supply chain attack. The malicious release 0.5.144 executed via a preinstall hook and loaded an obfuscated payload that could steal credentials and establish persistence.
The worm targets tokens and secrets across local files, CI systems, Kubernetes, and Vault. It also tries to propagate by forging provenance and republishing compromised versions. The incident highlights how a single tainted package can affect multiple services and environments.
What you should do now: remove the malicious tensorlake version, rotate affected credentials, and audit your dependency graph for tampering. If you install Tensorlake or related packages, check your CI workflows and repository settings for unexpected changes.
The Tensorlake npm package used by developers building Tensorlake applications was compromised as part of a supply chain attack known as ChainDrop, with the malicious release landing on October 7, 2026. The package, tensorlake, carried a credential‑stealing worm designed to harvest secrets from local machines, CI systems, Kubernetes clusters, and Vault sources. The worm also establishes persistence and can run remotely supplied code, making it dangerous even after a single install.
Overall, the attack expands the risk beyond a single API key or token. If an attacker gains access to credentials in one project, they may access other services and environments that share the same secrets. The worm is designed to enumerate the victim’s publishing identity, create forged provenance for GitHub Actions workflows, and republish compromised versions of related packages to propagate itself.
Security researchers say the malicious action was carefully layered. It used a preinstall hook to execute a JavaScript file, and an obfuscated loader to run the main payload named Math_Symbol.js via the Bun runtime. The malware also drops a tool called HackBrowserData and exfiltrates data to a remote endpoint, with GitHub acting as a fallback if the primary channel is unavailable.
Credential targets include npm tokens, GitHub tokens, AWS credentials and secrets, HashiCorp Vault data, Kubernetes credentials, SSH keys, and .env files. The malware can also reach into project configuration files and even wallets for cryptocurrency, broadening the potential damage across a developer’s tech stack.
As researchers noted, the worm uses the victim’s own resources to propagate. It builds Sigstore provenance to impersonate legitimate updates and suggests fake workflows tied to Copilot or Dependabot to help it exploit developer workflows. In some cases, GitHub data could be used as a staging ground for stolen material via a public repository, which complicates detection and cleanup.
Compromised projects were found under tensorlakeai/tensorlake, and the rogue release appeared on October 7, 2026, with the malicious version pushed shortly after. The Tensorlake team has removed the affected version from the registry, and researchers recommend rotating credentials and revoking tokens that may have been exposed. If you use tensorlake, you should inspect your dependencies for signs of tampering and consider rotating secrets across affected services.
What this means for everyday developers is straightforward: security teams should treat any recent npm package install in critical projects as potentially tainted until proven clean. Practically, that means auditing dependency trees, rotating access keys and tokens, and reviewing any GitHub Actions or CI workflows that might have been modified or added recently.
In short, this is a reminder that software supply chains can be weak links. The best defense is layered: monitor dependencies, limit privilege for tokens, rotate secrets regularly, and keep incident response plans handy so you can act fast if a compromised package is detected.
A UPS shipment carrying sensitive F-35 cockpit canopy and weapons-bay door components was allegedly rerouted through Hong Kong after an employee missed an ITAR alert, raising questions about secure handling of military tech.
Raheim Hamilton, co-creator of Empire Market, gets 40-year prison term for running a platform that facilitated hundreds of millions in illegal drug sales and other crimes.
3 min read
We use cookies to understand how readers use Talk With Tech, so we can make it better. Is that OK? Privacy policy
The Daily Brief
Today's biggest tech stories, in 5 minutes
Every morning, the news that matters from AI, phones, apps and the people shaping tech. Explained in plain English. Free.
One email a day. No spam, unsubscribe anytime. Privacy policy