Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm

A notorious npm package, Tensorlake, has been compromised to deliver a stealthy credential-stealing worm dubbed Shai-Hulud. The malicious update affects users who have installed the library in their projects, potentially exposing sensitive authentication credentials and paving the way for further attacks.

Tensorlake is an open-source JavaScript library used for image processing and computer vision tasks. However, its recent update, pushed out to npm on October 6th, has been found to be tainted with a malicious payload that exploits vulnerabilities in the package’s dependencies. The compromised code injects Shai-Hulud, a credential-stealing worm, into the affected systems.

The worm’s primary function is to extract sensitive authentication credentials from the compromised system and exfiltrate them to a remote server controlled by the attackers. This allows the attackers to gain access to the victim’s account and potentially spread further throughout the network. The malicious code has been designed to evade detection, making it challenging for security software to identify the threat.

Researchers have discovered that Shai-Hulud uses a sophisticated technique called cross-domain privilege escalation to gain elevated permissions on the compromised system. This allows the worm to move laterally within the network and exploit vulnerabilities in other applications or services. The attackers can use this access to create new backdoors, inject malware, or even take control of the entire system.

The compromised Tensorlake package has been downloaded over 1 million times from npm since its release, making it a significant threat vector for developers and organizations that rely on open-source libraries in their projects. If you have installed Tensorlake in your project, it is essential to update to a clean version or remove it entirely to prevent potential attacks.

To protect yourself against similar threats, ensure that all dependencies in your projects are regularly updated, and monitor npm package activity for suspicious updates. Additionally, consider implementing a vulnerability scanner to identify potential weaknesses in your codebase and take proactive measures to mitigate the risk of credential exposure. By staying informed about security best practices and keeping your software up-to-date, you can significantly reduce the likelihood of falling victim to malicious attacks like Shai-Hulud.


Source: The Hacker News — 2026-10-08