Shai-Hulud Worm Targets AI Infrastructure, Compromising Tensorlake SDK
The Shai-Hulud worm has infiltrated Tensorlake's npm SDK, a platform for AI agents, stealing credentials and cloud secrets, and posing a risk to thousands of weekly downloads.

The pervasive Shai-Hulud worm has once again demonstrated its adaptability, this time targeting the burgeoning field of artificial intelligence by compromising a popular SDK for the Tensorlake platform. Security researchers disclosed on Thursday that a recent release of Tensorlake's npm package, specifically version 0.5.144, contained malicious code attributed to the Shai-Hulud worm. This package, which garners approximately 12,000 downloads weekly and boasts over a thousand stars on its GitHub repository, represents a significant potential attack vector for developers working with AI agents.
Analysis of the compromised package indicates a strong resemblance to the ChainDrop variant of Shai-Hulud, which was previously used in August to compromise other npm dependencies like keyv and flat-cache. Like its predecessors, this new variant is engineered to pilfer sensitive information and to propagate itself across systems. Supply chain security firm SafeDep reported that the worm is capable of stealing a wide array of data, including cryptocurrency wallet credentials, browser passwords, cloud secrets, service account tokens, and GitHub Actions secrets.
Beyond mere data theft, the Shai-Hulud worm maintains persistent command-and-control (C2) communication with its operators, allowing for further instructions and potential exploitation. A particularly concerning feature of this variant is its ability to monitor certain stolen GitHub tokens. If these tokens are revoked by the user, the worm can, under specific conditions, trigger the deletion of the infected user's home directory, complicating recovery efforts and increasing the potential for data loss.
Tensorlake, the platform affected by this compromise, is designed to run isolated AI agents and untrusted AI-generated code in a cloud-native environment. The compromised npm SDK is integral to creating and managing these Tensorlake environments. Socket, a security firm that identified the malicious package, warned that the SDK's installation script can execute with the privileges of the installing process, potentially compromising the developer's machine or build server before any AI-generated code is even run, thereby bypassing Tensorlake's sandbox protections.
Fortunately, the malicious version of the Tensorlake SDK was short-lived. According to Socket, the infected package was published to npm earlier on Thursday and was flagged by their detection engine just 11 minutes after its release. In response to the discovery, npm swiftly removed the malicious version from its registry, and Tensorlake has also pulled the compromised package, releasing an updated version, 0.5.145, to replace it.
Despite the rapid response, users who may have installed the malicious version are urged to exercise caution. Socket recommends that compromised systems be rebuilt from a trusted source before restoring access to any secrets. Additionally, researchers advise disabling the malicious token monitoring feature within the worm before revoking any affected credentials to mitigate the risk of the home directory deletion.
The compromise of Tensorlake's SDK highlights the growing threat to AI infrastructure and the broader software supply chain. As AI development accelerates, the tools and platforms supporting it become increasingly attractive targets for sophisticated malware like Shai-Hulud, underscoring the need for robust security practices throughout the development lifecycle.