AI Agent SDK Hit by Worm's Latest Strike
Shai-Hulud worm compromised Tensorlake's npm SDK version 0.5.144, stolen credentials and cloud keys at risk for developers.
The Shai-Hulud credential-stealing worm has found a new target: the software development kits that power AI agent platforms. According to multiple security researchers, a recent release of Tensorlake's npm package was infected with the worm, marking a fresh escalation in supply chain attacks that now reach into the tooling used to build and run AI agents.
The compromised version, 0.5.144, was detected within minutes of its publication to the npm registry, but the potential fallout for developers who installed it remains unclear. Tensorlake is a cloud-native platform for running isolated AI agents and untrusted AI-authored code.
What the Worm Does
Analysis of the malicious release suggests it shares code and techniques with a Shai-Hulud variant that researchers have dubbed ChainDrop. That variant was used in August to compromise npm dependencies including keyv and flat-cache. Like other versions of Shai-Hulud, this worm is designed to steal credentials and self-propagate across systems.
According to supply chain security firm SafeDep, this particular version is built to harvest a wide range of sensitive data: crypto wallets, browser passwords, GitHub Actions secrets, cloud credentials, service-account tokens, and anything else it can access. It then exfiltrates that data and maintains an open connection to its command-and-control infrastructure, awaiting further instructions.
What makes this variant especially dangerous is its ability to monitor stolen GitHub tokens. If one of those tokens is revoked, the worm can trigger the deletion of the infected user's home directory under certain conditions, complicating cleanup efforts. Researchers advise disabling the malicious token monitor before revoking affected credentials.
Infection Vector and Scale
The infected npm package for Tensorlake's SDK is not a niche tool. It has roughly 12,000 downloads per week, and the corresponding GitHub repository has more than a thousand stars, indicating significant adoption among developers building AI agent workflows.
The SDK is used to create and manage Tensorlake environments. Security firm Socket warns that the malicious installation script can execute on the developer's machine or build server, outside Tensorlake's sandbox protections. This means the host could be compromised before any AI-generated code is even run.
Teams may isolate an agent’s generated code while installing its SDK on a developer workstation, application server, or build runner with access to deployment credentials and other secrets. Code executed during that installation inherits the permissions of the installing process.
— Socket, supply chain security firm
That warning highlights a structural weakness in how AI agent platforms are integrated into development pipelines. The sandboxing that protects against rogue AI code does not extend to the SDK installation itself, leaving credentials and secrets exposed on the host.
Swift Detection and Removal
The malicious version was not available for long. According to Socket, the infected package was published to npm earlier this morning, UTC, and its engine flagged it just 11 minutes after publication. npm subsequently removed the version, and Tensorlake pulled the package from its own distribution, updating to version 0.5.145.
Despite the quick takedown, the window of exposure was real. Any developer or build system that installed the package during those 11 minutes could have been compromised. Socket recommends rebuilding compromised systems from a trusted source before restoring access to secrets.
Who Is at Risk
Tensorlake users who installed version 0.5.144 of the npm SDK are the primary risk group. Because the installation script runs with the permissions of the installing process, the scope of a compromise depends on what that process could access. On a developer workstation, that might include browser-stored passwords and crypto wallets. On a build server or application server, it could mean deployment credentials, cloud service tokens, and GitHub Actions secrets.
The worm's self-propagating nature means an infection could spread beyond a single machine if those stolen credentials grant access to other systems or repositories. The token monitoring and deletion behavior adds a destructive twist, potentially wiping home directories if administrators revoke tokens without first disabling the monitor.
Recommendations for Affected Users
For those who may have installed the malicious version, the steps are clear. First, check whether version 0.5.144 was installed. If so, treat the system as compromised. Rebuild from a trusted source rather than attempting to clean the existing installation. Before revoking any GitHub tokens or other credentials that might be monitored by the worm, disable the malicious token monitor to avoid triggering the home directory deletion.
Socket's guidance emphasizes rebuilding before restoring access to secrets, a sequence that prevents re-infection from lingering malicious code. Developers should also review any credentials that were accessible to the installing process and rotate them as a precaution.
The Broader Shai-Hulud Campaign
This is not the first time Shai-Hulud has struck npm. The ChainDrop variant used in August targeted keyv and flat-cache, and this latest infection reuses code and techniques from that campaign. The worm's ability to steal credentials and self-propagate has made it a persistent threat to open source supply chains.
The jump to an AI infrastructure SDK is notable because it targets a growing category of tooling that often sits at the intersection of development environments and cloud services. These SDKs frequently require broad permissions to manage environments and deploy agents, making them attractive targets for credential theft.
Why This Matters Beyond Tensorlake
The Tensorlake compromise is a reminder that supply chain attacks are evolving to target the specialized tools that developers rely on. For businesses building AI agents, the incident highlights the importance of monitoring dependencies for malicious releases and understanding the permissions granted during installation. The 11-minute detection window shows that rapid response is possible, but it also means that any delay in removing a compromised package can lead to credential theft.
For the industry, this could signal that AI infrastructure is becoming a more attractive target for attackers seeking high-value credentials. Developers and security teams may need to extend their supply chain security practices to cover SDK installations and build-time scripts, not just runtime code. As AI agent platforms continue to gain adoption, the security of their underlying tooling will be a critical part of the defense.
Sources
- The Register Original source
Continue Reading
FBI Ties Chinese Firm to Email Theft Portal
A joint advisory says hackers linked to Integrity Technology Group stole email and ran a web app giving third parties access to it.
Ransomware Crews Face Betrayal From Within
A Gentlemen affiliate pocketed extortion profits on a private leak site, as a week of supply chain and phishing threats piled up.
ASOS breach traced to impersonation tactic
ASOS says an employee's stolen credentials, obtained through social engineering, exposed names and contact details held on third-party platforms.