<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Tensorlake (0.5.144) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/tensorlake-0.5.144/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 08 Oct 2026 19:57:44 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/tensorlake-0.5.144/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Malicious TensorLake npm SDK Hijacks Developer Environments</title><link>https://feed.craftedsignal.io/briefs/2026-10-tensorlake-compromise/</link><pubDate>Thu, 08 Oct 2026 19:57:44 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-tensorlake-compromise/</guid><description>A malicious npm release of the TensorLake TypeScript SDK (v0.5.144) uses a preinstall hook to exfiltrate developer credentials and AI-tool configurations while maintaining remote command execution capabilities.</description><content:encoded><![CDATA[<p>A malicious version of the TensorLake TypeScript SDK, identified as <a href="mailto:tensorlake@0.5.144">tensorlake@0.5.144</a>, was distributed via the npm registry. The package contains a obfuscated JavaScript payload triggered by a preinstall hook, which attempts to download the Bun runtime if not already present on the host system. The primary goal of the payload is the theft of sensitive developer credentials, including GitHub tokens and HashiCorp Vault secrets, alongside configuration files for various AI-assisted development tools like Claude, Cursor, and Kiro MCP. The malware includes a command-and-control mechanism that allows for arbitrary JavaScript evaluation. Notably, the payload includes logic to exfiltrate collected data by creating public GitHub repositories and committing stolen tokens to them. While the payload includes checks to avoid execution in common CI/CD environments, it actively targets developer workstations for potential lateral movement and persistence through the modification of .vscode and .claude configuration files within local repositories.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Victim installs the malicious package <a href="mailto:tensorlake@0.5.144">tensorlake@0.5.144</a>, triggering the 'preinstall' hook defined in package.json.</li>
<li>The hook executes an obfuscated 'setup.mjs' script, which checks for CI/CD environment variables to determine if it should proceed.</li>
<li>The script downloads or invokes the Bun runtime to execute the malicious JavaScript payload.</li>
<li>The payload performs local reconnaissance to identify stored GitHub tokens, HashiCorp Vault credentials, and configuration files for AI coding assistants.</li>
<li>The malware establishes a command-and-control channel to poll for and execute remote JavaScript commands.</li>
<li>The code attempts to exfiltrate harvested secrets by creating a public GitHub repository and committing data to a 'results/' directory.</li>
<li>The payload modifies project-level configuration files (.vscode, .claude) in accessible repositories to establish persistence or facilitate downstream execution.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation leads to the exposure of high-privilege credentials, including GitHub tokens and HashiCorp Vault secrets, potentially enabling unauthorized access to private corporate infrastructure. The injection of configuration files into local repositories poses a significant risk of downstream contamination, allowing the malicious code to spread to other developers who interact with the compromised codebases. No broad CI/CD infection has been confirmed, but the potential for developer environment compromise is severe.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Identify all instances of 'tensorlake@0.5.144' in local environments, CI/CD runners, and package lockfiles.</li>
<li>Search for the presence of 'globalThis.WORMTAG' with the value 'tensrlake' in active memory or running processes to identify affected systems.</li>
<li>Treat all credentials accessible to developers who installed the package as compromised; rotate GitHub tokens and HashiCorp Vault secrets immediately.</li>
<li>Audit GitHub repository activity for unauthorized repository creation or anomalous commits to '.vscode', '.claude', and 'results/' directories.</li>
<li>Inspect developer workstations for unexpected 'preinstall' hook executions during npm package installation.</li>
<li>Implement egress filtering to block communication to suspicious command-and-control infrastructure identified via forensic analysis of the 'setup.mjs' payload.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>supply-chain</category><category>npm</category><category>credential-theft</category><category>javascript</category></item></channel></rss>