{
  "id": 12932896,
  "title": "Shai-Hulud worm makes jump to AI infrastructure with Tensorlake compromise",
  "url": "https://urgent.news/2026/10/08/shai-hulud-worm-makes-jump-to-ai-infrastructure-with-tensorlake-12932896",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-08T16:54:48.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/security/2026/10/08/shai-hulud-worm-makes-jump-to-ai-infrastructure-with-tensorlake-compromise/5302054"
  },
  "original_language": "en",
  "account": "A credential-hijacking worm named Shai-Hulud has infiltrated a widely-used AI agent platform SDK, posing a significant threat to users and their data. Researchers discovered the malware in the npm package for Tensorlake’s SDK version 0.5.144, which has been downloaded approximately 12,000 times weekly and boasts a thousand stars on GitHub, indicating its popularity. The malicious release shares similarities with a previous Shai-Hulud variant, ChainDrop, utilized in an August attack on npm dependencies such as keyv and flat-cache. This new variant is capable of stealing a wide array of credentials, including crypto wallets, browser passwords, GitHub Actions secrets, cloud credentials, service-account tokens, and other sensitive information. It then transmits the stolen data to its command and control (C2) infrastructure for further instructions.\n\nThe worm's ability to monitor stolen GitHub tokens poses an additional challenge for users, as it can potentially delete the infected user's home directory if a revoked token is detected, complicating the removal process. Socket, a security recommendation firm, advises users to rebuild compromised systems from a trusted source before restoring access to secrets. Researchers recommend disabling the malicious token monitor before revoking affected credentials.\n\nTensorlake, an AI-focused cloud-native platform, uses the affected SDK to create and manage environments for AI agents and untrusted AI-authored code. The SDK's installation script can execute on developers' machines or build servers, outside Tensorlake's sandbox protections, risking the compromise of host systems and any secrets accessed during the installation process. Socket warns that installation scripts of the malicious SDK can bypass Tensorlake's security measures, potentially exposing sensitive information.\n\nFortunately, the malicious version of the SDK was only published to npm earlier this morning in UTC and was quickly flagged and removed by the npm engine within 11 minutes of publication. Tensorlake has also pulled the package and updated it to version 0.5.145. Tensorlake users are strongly advised to verify their installations to ensure they have not downloaded the malicious version.",
  "summary": "Credential-stealing malware detected within minutes of npm release, but impact remains unknown",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "Shai-Hulud worm makes jump to AI infrastructure with Tensorlake compromise",
        "url": "https://urgent.news/2026/10/08/shai-hulud-worm-makes-jump-to-ai-infrastructure-with-tensorlake",
        "published": "2026-10-08T16:54:48.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}