Malicious TensorLake npm SDK Hijacks Developer Environments
A malicious npm release of the TensorLake TypeScript SDK (v0.5.144) uses a preinstall hook to exfiltrate developer credentials and AI-tool configurations while maintaining remote command execution capabilities.
A malicious version of the TensorLake TypeScript SDK, identified as tensorlake@0.5.144, was distributed via the npm registry. The package contains a obfuscated JavaScript payload triggered by a preinstall hook, which attempts to download the Bun runtime if not already present on the host system. The primary goal of the payload is the theft of sensitive developer credentials, including GitHub tokens and HashiCorp Vault secrets, alongside configuration files for various AI-assisted development tools like Claude, Cursor, and Kiro MCP. The malware includes a command-and-control mechanism that allows for arbitrary JavaScript evaluation. Notably, the payload includes logic to exfiltrate collected data by creating public GitHub repositories and committing stolen tokens to them. While the payload includes checks to avoid execution in common CI/CD environments, it actively targets developer workstations for potential lateral movement and persistence through the modification of .vscode and .claude configuration files within local repositories.
Attack Chain
- Victim installs the malicious package tensorlake@0.5.144, triggering the 'preinstall' hook defined in package.json.
- The hook executes an obfuscated 'setup.mjs' script, which checks for CI/CD environment variables to determine if it should proceed.
- The script downloads or invokes the Bun runtime to execute the malicious JavaScript payload.
- The payload performs local reconnaissance to identify stored GitHub tokens, HashiCorp Vault credentials, and configuration files for AI coding assistants.
- The malware establishes a command-and-control channel to poll for and execute remote JavaScript commands.
- The code attempts to exfiltrate harvested secrets by creating a public GitHub repository and committing data to a 'results/' directory.
- The payload modifies project-level configuration files (.vscode, .claude) in accessible repositories to establish persistence or facilitate downstream execution.
Impact
Successful exploitation leads to the exposure of high-privilege credentials, including GitHub tokens and HashiCorp Vault secrets, potentially enabling unauthorized access to private corporate infrastructure. The injection of configuration files into local repositories poses a significant risk of downstream contamination, allowing the malicious code to spread to other developers who interact with the compromised codebases. No broad CI/CD infection has been confirmed, but the potential for developer environment compromise is severe.
Recommendation
- Identify all instances of 'tensorlake@0.5.144' in local environments, CI/CD runners, and package lockfiles.
- Search for the presence of 'globalThis.WORMTAG' with the value 'tensrlake' in active memory or running processes to identify affected systems.
- Treat all credentials accessible to developers who installed the package as compromised; rotate GitHub tokens and HashiCorp Vault secrets immediately.
- Audit GitHub repository activity for unauthorized repository creation or anomalous commits to '.vscode', '.claude', and 'results/' directories.
- Inspect developer workstations for unexpected 'preinstall' hook executions during npm package installation.
- Implement egress filtering to block communication to suspicious command-and-control infrastructure identified via forensic analysis of the 'setup.mjs' payload.
Immediate actions
Audit GitHub audit logs for repository modifications
Threat Hunt
Search for 'globalThis.WORMTAG' with value 'tensrlake'
Data: Process memory dumps, Runtime logs
Mitigations
Rotate all credentials accessible to developer environments
GitHub and HashiCorp Vault tokens
Gaps
- Telemetry for credential access from within Node processes
Detection coverage 1
Detect Malicious TensorLake Preinstall Hook
highDetects the execution of the malicious tensorlake@0.5.144 package via its preinstall script hook
Detection queries are available on the platform. Get full rules →