Shai-Hulud, the notorious malware that has struck multiple times, is back. The worm spread via an infected npm SDK from the AI platform Tensorlake. This platform allows users to run agents in isolation. Among other things, the malware steals credentials and deletes critical directories. Researchers at Socket discovered the infection within 11 minutes.
Yesterday, the researchers discovered Shai-Hulud malware in version 0.5.144 of the npm package for Tensorlake’s SDK. That package averages about 12,000 downloads per week, a significant reach given the specialized nature of this type of developer tooling. The GitHub repository has more than a thousand stars. Tensorlake is a cloud-native platform for running AI agents and AI-generated code in isolation. Developers use the SDK to create and manage these environments as needed.
The compromised version was therefore online for only a short time thanks to Socket.l’s quick response. npm removed the version after receiving the prompt report; Tensorlake also withdrew the package and released version 0.5.145.
Outside the sandbox
Socket points out a troubling detail: the installation script for the compromised SDK runs on the developer’s machine or on a build server, outside of Tensorlake’s sandbox. While Teams does isolate the code generated by an agent, it installs the SDK itself on workstations or build runners with access to deployment credentials. Code that runs during that installation inherits the permissions of that process.
According to SafeDep, as cited by The Register, Shai Hulud then steals virtually everything of digital value. This includes, among other things, crypto wallets, browser passwords, GitHub Actions secrets, cloud credentials, and service account tokens. The loot is sent to the attackers’ C2 infrastructure, after which the malware maintains an open connection to receive new instructions. In doing so, this variant monitors certain stolen GitHub tokens. If such a token is revoked, the malware can, under specific circumstances, wipe the victim’s home directory. Researchers therefore advise disabling the token monitor initially. Socket recommends rebuilding affected systems from a trusted source.
Known family
The code shows similarities to ChainDrop, a Shai-Hulud variant that compromised npm dependencies such as keyv and flat-cache in August. Shai-Hulud itself emerged in September 2025, and at the time, CISA identified more than 500 compromised packages. Two months later, Shai-Hulud 2.0 followed, affecting more than a thousand package versions and introducing the destructive deletion function. Shortly thereafter, Shai-Hulud 3.0 appeared. Even aside from these incidents, npm remained a target, including the hijacking of the Axios package and malicious code in Red Hat’s npm packages.