Tensorlake's npm SDK was hijacked on October 8, when a poisoned release began delivering a credential stealer that also tries to spread itself to other packages. The SDK is how TypeScript developers create and manage Tensorlake's isolated sandboxes for running untrusted, LLM-generated code. A compromised copy runs on the laptop, app server or build runner that installs it, which often holds more valuable secrets than any sandbox does.
Per Socket, the bad build is tensorlake version 0.5.144, published at 01:12 UTC on October 8 and flagged by its scanners about 11 minutes later. The package pulls roughly 12,000 downloads a week, a figure Socket says describes overall usage, not installs of the malicious version, so the number of affected machines is unknown. A preinstall hook launches an obfuscated loader, lib/setup.mjs, which means a developer never has to import the SDK or start an agent for the code to run wherever dependency lifecycle scripts are allowed.
Socket's analysis describes a broad harvester. It goes after npm and GitHub tokens, AWS credentials and secrets, HashiCorp Vault, Kubernetes service-account tokens, SSH keys, .env files, cryptocurrency wallets and the configuration files of AI coding tools such as Claude, Cursor, Kiro, Windsurf and Zed. To spread, the worm lists the packages tied to the victim's publishing identity and republishes poisoned versions with Sigstore provenance attached. It has no hardcoded command server; it looks up its endpoint through an Ethereum contract across about 30 public RPC endpoints, with a GitHub fallback.
The file names and structure match the August compromises of keyv and cacheable, Socket notes, where the same setup.mjs loader started an obfuscated Math_Symbol.js payload. What is new here is the target. Tensorlake sells infrastructure for AI agents, and the incident shows that isolating generated code does nothing for the machine that installs the tooling around it.
Cleanup carries a trap. Socket says the payload installs a token monitor that polls GitHub with a stolen token and, once that token is revoked, runs an attacker-supplied handler; the code also contains a string threatening to wipe the owner's computer. Teams that find tensorlake 0.5.144 in lockfiles, build logs or deployed artifacts should treat the host as compromised, remove the gh-token-monitor persistence first (a systemd unit on Linux, a launch agent on macOS, a logon scheduled task on Windows), and only then revoke and replace credentials. Revoking first can set off the home-directory wipe.












