SafeDep reported on October 8 that version 0.5.144 of the tensorlake npm package carried a credential-stealing worm that runs at install time. The package has about 106,000 monthly downloads, according to SafeDep.

What happened

SafeDep’s automated analysis flagged the release eight minutes after npm recorded it. The company says the payload is a new build of Mini Shai-Hulud, the 2026 wave of the Shai-Hulud worm family, and that it steals cloud, GitHub, npm, SSH, browser and wallet credentials, spreads through npm packages and GitHub repositories, and runs remote code from its command-and-control server.

SafeDep says the attacker did not need an npm token. According to its analysis, they used a repository administrator account to commit the payload through the GitHub web interface and then ran the project’s own release workflow. npm removed the version, and SafeDep says the maintainers reverted the source in pull request 1016 and released 0.5.145. SafeDep also says the loader skips CI runners, so the payload probably did not run in the project’s own build job.

Why it matters

The release used npm trusted publishing, and SafeDep says sibling packages from the same run carry valid provenance, which attests only that the build came from the project’s workflow. The provenance was valid for poisoned source. That connects to our argument about starting the patch clock on release day, and to our reporting on AI coding agents exposing internal material on GitHub.

One original point

Provenance answers where a package was built, not whether the people with admin rights were the people you expect. A team that auto-updates on the strength of an attested release is also trusting every administrator account on that repository.

What to do

Check lockfiles and build logs for tensorlake 0.5.144 and move to 0.5.145 or later. On any machine that installed it outside CI, SafeDep advises removing the worm’s gh-token-monitor persistence before revoking GitHub tokens, because it says the monitor deletes the home directory when a stolen token is revoked. Then rotate cloud, npm, SSH and GitHub credentials from a clean machine.

Source: SafeDep, October 8, 2026