tensorlake@0.5.144
Malicious code in tensorlake (npm)
Analysis
The published tarball of this SDK carries an injected preinstall hook (`node lib/setup.mjs`) that loads an obfuscated 856 KB payload, `lib/Math_Symbol.js`. The payload sets a global marker (`globalThis.WORMTAG='tensrlake'`) and then harvests credentials from the installing machine: `~/.npmrc` and `.npmrc`, `~/.aws/credentials`, `~/.ssh/id_rsa` and `~/.ssh/authorized_keys`, `~/.git-credentials`, `~/.vault-token`, `~/.terraform.d/credentials.tfrc.json`, `~/.config/gcloud/credentials.db` and `application_default_credentials.json`, `/root/.kube/config`, `~/.config/solana/id.json`, `~/.foundry/keystores/*`, `~/.cosmos/config/priv_validator_key.json`, `~/.config/sui/sui_config/sui.keystore`, `~/.keplr/*`, `~/.electrum*/wallets/*`, `~/.config/Exodus/exodus.wallet/*`, `~/Library/Application Support/MetaMask/*`, `~/.ledger/config.json`, `~/.config/1Password/1password.sqlite`, `~/.local/share/keyrings/login.keyring`, Firefox `key4.db`, and a long list of AI/CI CLI config files (`~/.codex/config.toml`, `~/.gemini/config.json`, `~/.cursor/cli-config.json`, `~/.codeium/config.json`, `~/.continue/config.json`, `~/.circleci/cli.yml`, `~/.config/hardhat/config.json`). It also reads CI environment variables (GITHUB_TOKEN, GITHUB_WORKFLOW_REF, GITHUB_REPOSITORY, GITLAB_CI, CI, VAULT_TOKEN, VAULT_AUTH_TOKEN), uses the stolen npm token to enumerate the victim's published packages and scopes with write access, and uses the stolen GitHub token against api[.]github[.]com to fetch repository contents and commit/push files into the victim's own repositories — worm-style self-propagation. It writes `~/.ssh/authorized_keys` for persistence and fingerprints the host (hostname, username, OS, cwd, locale). The hook deliberately returns early when CI, GITHUB_ACTIONS or GITLAB_CI is set, so it stays dormant inside build pipelines and only executes on developer workstations. Transport endpoints observed: api[.]github[.]com and registry[.]npmjs[.]org, abused as the exfiltration and propagation channel; no attacker-owned C2 domain is present.
- analyzed by
- Leitwacht
- first seen
- Oct 8, 2026, 01:12 AM
- analyzed
- Oct 8, 2026, 11:03 AM
- weekly installs
- 18,826
Related advisories
- ts-ankle@1.1.0
- zenith-utils@12.0.14
- moidevz@1.0.0
- hydration-vli-ui@1.0.0
- hydration-cls-ui@1.0.0
- hydration-dim-ui@1.0.0
- totp-utils@1.4.3
- kit-map-vim@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.