The npm package "tensorlake," a TypeScript software development kit for Tensorlake applications, was compromised as part of a ChainDrop / Shai-Hulud supply chain attack, based on information published by The Hacker News.
The malicious version 0.5.144 of the tensorlake package contained obfuscated malware designed to harvest credentials, exfiltrate secrets, establish persistence, and execute remotely supplied code. The malware targeted a wide range of sensitive information, including npm tokens, GitHub tokens, AWS credentials, Kubernetes credentials, SSH keys, cryptocurrency wallets, and configuration files for AI tools like Anthropic Claude. It also dropped the HackBrowserData binary and used an Ethereum contract for command-and-control, with GitHub as a fallback. The attack propagated by enumerating associated packages, building Sigstore provenance, and republishing compromised versions. This incident extends the supply chain attack to AI agent infrastructure, highlighting the increasing trend of threat actors targeting AI tools and services for data extraction. Users who installed the malicious version are advised to remove it immediately and rotate their credentials.
Source: The Hacker News
