{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/tensorlake-0.5.144/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["tensorlake (0.5.144)","GitHub","HashiCorp Vault"],"_cs_severities":["high"],"_cs_tags":["supply-chain","npm","credential-theft","javascript"],"_cs_type":"advisory","_cs_vendors":["GitHub","HashiCorp"],"content_html":"\u003cp\u003eA malicious version of the TensorLake TypeScript SDK, identified as \u003ca href=\"mailto:tensorlake@0.5.144\"\u003etensorlake@0.5.144\u003c/a\u003e, was distributed via the npm registry. The package contains a obfuscated JavaScript payload triggered by a preinstall hook, which attempts to download the Bun runtime if not already present on the host system. The primary goal of the payload is the theft of sensitive developer credentials, including GitHub tokens and HashiCorp Vault secrets, alongside configuration files for various AI-assisted development tools like Claude, Cursor, and Kiro MCP. The malware includes a command-and-control mechanism that allows for arbitrary JavaScript evaluation. Notably, the payload includes logic to exfiltrate collected data by creating public GitHub repositories and committing stolen tokens to them. While the payload includes checks to avoid execution in common CI/CD environments, it actively targets developer workstations for potential lateral movement and persistence through the modification of .vscode and .claude configuration files within local repositories.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eVictim installs the malicious package \u003ca href=\"mailto:tensorlake@0.5.144\"\u003etensorlake@0.5.144\u003c/a\u003e, triggering the 'preinstall' hook defined in package.json.\u003c/li\u003e\n\u003cli\u003eThe hook executes an obfuscated 'setup.mjs' script, which checks for CI/CD environment variables to determine if it should proceed.\u003c/li\u003e\n\u003cli\u003eThe script downloads or invokes the Bun runtime to execute the malicious JavaScript payload.\u003c/li\u003e\n\u003cli\u003eThe payload performs local reconnaissance to identify stored GitHub tokens, HashiCorp Vault credentials, and configuration files for AI coding assistants.\u003c/li\u003e\n\u003cli\u003eThe malware establishes a command-and-control channel to poll for and execute remote JavaScript commands.\u003c/li\u003e\n\u003cli\u003eThe code attempts to exfiltrate harvested secrets by creating a public GitHub repository and committing data to a 'results/' directory.\u003c/li\u003e\n\u003cli\u003eThe payload modifies project-level configuration files (.vscode, .claude) in accessible repositories to establish persistence or facilitate downstream execution.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to the exposure of high-privilege credentials, including GitHub tokens and HashiCorp Vault secrets, potentially enabling unauthorized access to private corporate infrastructure. The injection of configuration files into local repositories poses a significant risk of downstream contamination, allowing the malicious code to spread to other developers who interact with the compromised codebases. No broad CI/CD infection has been confirmed, but the potential for developer environment compromise is severe.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eIdentify all instances of 'tensorlake@0.5.144' in local environments, CI/CD runners, and package lockfiles.\u003c/li\u003e\n\u003cli\u003eSearch for the presence of 'globalThis.WORMTAG' with the value 'tensrlake' in active memory or running processes to identify affected systems.\u003c/li\u003e\n\u003cli\u003eTreat all credentials accessible to developers who installed the package as compromised; rotate GitHub tokens and HashiCorp Vault secrets immediately.\u003c/li\u003e\n\u003cli\u003eAudit GitHub repository activity for unauthorized repository creation or anomalous commits to '.vscode', '.claude', and 'results/' directories.\u003c/li\u003e\n\u003cli\u003eInspect developer workstations for unexpected 'preinstall' hook executions during npm package installation.\u003c/li\u003e\n\u003cli\u003eImplement egress filtering to block communication to suspicious command-and-control infrastructure identified via forensic analysis of the 'setup.mjs' payload.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-08T19:57:44Z","date_published":"2026-10-08T19:57:44Z","id":"https://feed.craftedsignal.io/briefs/2026-10-tensorlake-compromise/","summary":"A malicious npm release of the TensorLake TypeScript SDK (v0.5.144) uses a preinstall hook to exfiltrate developer credentials and AI-tool configurations while maintaining remote command execution capabilities.","title":"Malicious TensorLake npm SDK Hijacks Developer Environments","url":"https://feed.craftedsignal.io/briefs/2026-10-tensorlake-compromise/"}],"language":"en","title":"CraftedSignal Threat Feed - Tensorlake (0.5.144)","version":"https://jsonfeed.org/version/1.1"}