SOC Prime Bias: Critical

09 Oct 2026 07:24 UTC

Shai-Hulud Supply Chain Attack Targets TensorLake npm SDK

Author Photo
SOC Prime Team linkedin icon Follow
Shai-Hulud Supply Chain Attack Targets TensorLake npm SDK
shield icon

Detection stack

  • AIDR
  • Alert
  • ETL
  • Query

Summary

A compromised release of the Tensorlake npm SDK, version 0.5.144, was discovered in a supply chain attack linked to ChainDrop / Shai-Hulud. The malicious package abuses a preinstall hook to launch an obfuscated loader that deploys a credential-stealing worm. The malware targets authentication tokens, cloud credentials, and AI development tool configurations while also incorporating a destructive dead-man switch.

Investigation

Socket Research detected the compromise after identifying a malicious preinstall hook within the package manifest. Analysis showed that the loader uses Bun to execute a payload capable of harvesting credentials and propagating through npm. Researchers also uncovered a PowerShell-based persistence technique and an Ethereum-based method for resolving command-and-control infrastructure.

Mitigation

Users should immediately block and remove Tensorlake version 0.5.144 and audit every environment where its installation script may have executed. The gh-token-monitor persistence mechanism should be removed before revoking compromised GitHub tokens to avoid triggering the dead-man switch and potential directory deletion. Organizations should also rotate exposed secrets, including AWS, GitHub, and Kubernetes credentials.

Response

Any host that executed the malicious code should be treated as fully compromised and isolated for further investigation. Remove identified persistence files and scheduled tasks across Linux, macOS, and Windows systems. Once persistence has been eliminated, perform a complete credential rotation and rebuild affected environments from trusted, known-good sources.

Attack Flow

We are still updating this part.

Detections

Possible Github File Downloading Initiated By Unusual Process (via network_connection)

SOC Prime Team
08 Oct 2026

Suspicious Scheduled Task (via audit)

SOC Prime Team
08 Oct 2026

IOCs (HashSha256) to detect: TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack

SOC Prime AI Rules
08 Oct 2026

Detection of gh-token-monitor Service for Persistence [Microsoft Windows Security Event Log]

SOC Prime AI Rules
08 Oct 2026

Credential Harvesting via AWS Metadata and Secrets Manager [AWS Cloudtrail]

SOC Prime AI Rules
08 Oct 2026

Detection of Obfuscated Credential-Stealing and Self-Propagating Worm in TensorLake npm SDK [Linux File Event]

SOC Prime AI Rules
08 Oct 2026

Simulation Execution

  • Attack Narrative & Commands: The adversary has successfully gained initial access and is looking to establish persistence. Following the Shai-Hulud methodology, the attacker drops a malicious binary named gh-token-monitor into a hidden directory (e.g., /tmp/.hidden/). The goal is to run this process to monitor GitHub tokens, which would allow for further credential harvesting and lateral movement. The attacker executes the binary to establish its presence, which should trigger the detection rule based on the filename.

  • Regression Test Script:

    #!/bin/bash
    # Create a hidden directory to mimic adversary behavior
    mkdir -p /tmp/.hidden/
    
    # Create a dummy binary named gh-token-monitor
    echo -e '#!/bin/bashnecho "Monitoring GitHub tokens..."nsleep 3600' > /tmp/.hidden/gh-token-monitor
    
    # Make the dummy binary executable
    chmod +x /tmp/.hidden/gh-token-monitor
    
    # Execute the binary to trigger the detection rule
    /tmp/.hidden/gh-token-monitor &
    
    # Capture the PID to allow for cleanup
    ATTACK_PID=$!
    echo "Simulation running with PID: $ATTACK_PID"
    sleep 5
    kill $ATTACK_PID
  • Cleanup Commands:

    # Remove the malicious directory and dummy binary
    rm -rf /tmp/.hidden/