On 8 October 2026, the official npm package for Tensorlake — a TypeScript SDK used by developers building on the Tensorlake document-processing platform — shipped a poisoned release, version 0.5.144. The malicious update carried a payload from the Shai-Hulud family, a self-propagating credential-stealing worm that has resurfaced several times on npm over the past year, most recently in a bigger attack on the keyv caching library and its related packages in August.
The attack ran through a preinstall hook, meaning the malicious code executed automatically the moment anyone ran npm install on the compromised version — no further action required from the developer. Once running, it harvested npm publishing tokens, GitHub tokens, AWS credentials, HashiCorp Vault secrets, Kubernetes credentials, SSH keys, and configuration files for AI coding tools including Claude, Cursor, Kiro and Windsurf, then attempted to spread further using whatever publishing access it found. Researchers at Socket, Endor Labs, Aikido and others say the most likely root cause is a compromised maintainer account on the project's GitHub Actions pipeline: once the attacker altered the source, the project's own trusted automation built and published the tainted package, complete with valid-looking provenance. npm removed version 0.5.144 once the compromise was reported; 0.5.143, the version published before it, is clean.
What this means for your business
If you or a contractor working on your behalf installed tensorlake on or after 8 October, treat every credential reachable from that machine as exposed — not just the obvious ones. Rotate npm and GitHub tokens, cloud (AWS) keys, SSH keys, and any Vault or Kubernetes secrets the machine had access to, then check your CI/CD logs for any publish or push you didn't make yourself. If you don't recognise the package name, it's still worth a five-minute check: ask whoever manages your codebase to run npm ls tensorlake across your projects, including ones that aren't actively maintained, since those are exactly the ones nobody's watching for an unexpected update.
The broader pattern matters more than this one package. Shai-Hulud-style worms keep returning because the preinstall-hook trick works almost every time, and a single compromised maintainer account can poison a package in minutes. A standing habit of pinning dependency versions rather than always pulling "latest," and reviewing changelogs before a routine update, costs a developer very little and would have caught this one before it ran.