Shai-Hulud Supply Chain Attack Targets TensorLake npm SDK
Detection stack
- AIDR
- Alert
- ETL
- Query
Summary
A compromised release of the Tensorlake npm SDK, version 0.5.144, was discovered in a supply chain attack linked to ChainDrop / Shai-Hulud. The malicious package abuses a preinstall hook to launch an obfuscated loader that deploys a credential-stealing worm. The malware targets authentication tokens, cloud credentials, and AI development tool configurations while also incorporating a destructive dead-man switch.
Investigation
Socket Research detected the compromise after identifying a malicious preinstall hook within the package manifest. Analysis showed that the loader uses Bun to execute a payload capable of harvesting credentials and propagating through npm. Researchers also uncovered a PowerShell-based persistence technique and an Ethereum-based method for resolving command-and-control infrastructure.
Mitigation
Users should immediately block and remove Tensorlake version 0.5.144 and audit every environment where its installation script may have executed. The gh-token-monitor persistence mechanism should be removed before revoking compromised GitHub tokens to avoid triggering the dead-man switch and potential directory deletion. Organizations should also rotate exposed secrets, including AWS, GitHub, and Kubernetes credentials.
Response
Any host that executed the malicious code should be treated as fully compromised and isolated for further investigation. Remove identified persistence files and scheduled tasks across Linux, macOS, and Windows systems. Once persistence has been eliminated, perform a complete credential rotation and rebuild affected environments from trusted, known-good sources.
Attack Flow
We are still updating this part.
Detections
Possible Github File Downloading Initiated By Unusual Process (via network_connection)
Suspicious Scheduled Task (via audit)
IOCs (HashSha256) to detect: TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Detection of gh-token-monitor Service for Persistence [Microsoft Windows Security Event Log]
Credential Harvesting via AWS Metadata and Secrets Manager [AWS Cloudtrail]
Detection of Obfuscated Credential-Stealing and Self-Propagating Worm in TensorLake npm SDK [Linux File Event]
Simulation Execution
-
Attack Narrative & Commands: The adversary has successfully gained initial access and is looking to establish persistence. Following the Shai-Hulud methodology, the attacker drops a malicious binary named
gh-token-monitorinto a hidden directory (e.g.,/tmp/.hidden/). The goal is to run this process to monitor GitHub tokens, which would allow for further credential harvesting and lateral movement. The attacker executes the binary to establish its presence, which should trigger the detection rule based on the filename. -
Regression Test Script:
#!/bin/bash # Create a hidden directory to mimic adversary behavior mkdir -p /tmp/.hidden/ # Create a dummy binary named gh-token-monitor echo -e '#!/bin/bashnecho "Monitoring GitHub tokens..."nsleep 3600' > /tmp/.hidden/gh-token-monitor # Make the dummy binary executable chmod +x /tmp/.hidden/gh-token-monitor # Execute the binary to trigger the detection rule /tmp/.hidden/gh-token-monitor & # Capture the PID to allow for cleanup ATTACK_PID=$! echo "Simulation running with PID: $ATTACK_PID" sleep 5 kill $ATTACK_PID -
Cleanup Commands:
# Remove the malicious directory and dummy binary rm -rf /tmp/.hidden/