Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-10-09 · updated: 2026-10-09 · tags: [incident, global, supply-chain] · confidence: high · severity: critical · affected_sectors: [global] · au_impact: true
🎯 IOCs · Shai-Hulud
Indicators of compromise · Shai-Hulud — 2 shown
  • 25a0735d0db7dc40e5d45ce42d9c106067e6a66e184d967cfecfab17c3bcb5efsha256 · ThreatFox · first seen 2026-10-08
  • b50a00900399ba99fb6ce1fc151519cb99d44320ef2a631f2237e1aea0ad6fecsha256 · ThreatFox · first seen 2026-10-08

Defanged third-party indicators (abuse.ch). The defanging is deliberate: never click, resolve or fetch these values. An indicator corroborates a report — it never proves one, and its presence here does not mean this story's hosts are listed.

Security researchers flagged on 8 October that version 0.5.144 of the npm SDK for Tensorlake — a cloud platform for running isolated AI agents and untrusted AI-generated code — was published carrying the Shai-Hulud credential-stealing worm, sharing code and techniques with the ChainDrop variant used in August against npm dependencies including keyv and flat-cache. The release, on a package downloaded roughly 12,000 times a week from a repository with more than a thousand stars, was detected by Socket's engine 11 minutes after publication and removed by npm; Tensorlake pulled it and shipped 0.5.145. Analysis by supply-chain firm SafeDep found the release steals crypto wallets, browser passwords, GitHub Actions secrets, cloud credentials and service-account tokens, exfiltrates them and holds a command-and-control channel open — and a token-monitoring feature can trigger deletion of an infected user's home directory under specific conditions when a stolen GitHub token is revoked, so researchers warn it must be disabled before rotating credentials. Socket stresses that the install script runs outside Tensorlake's sandbox, on the developer workstation, application server or build runner that installs it, inheriting that machine's permissions. The OpenSourceMalware archive independently holds a critical record for tensorlake 0.5.144, first seen 8 October.

Attribute Detail
Sector Global (Macro)
Date 2026-10-09
Source The Register
Reliability Tier 2