LWA-2026-12664 MAL-2026-17650 ↗ confirmed malware

tensorlake@0.5.144

Malicious code in tensorlake (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1546 · Event Triggered ExecutionT1098.004 · SSH Authorized KeysT1552.001 · Credentials In FilesT1552.004 · Private KeysT1555.003 · Credentials from Web BrowsersT1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1071.001 · Web ProtocolsT1102 · Web ServiceT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 ChannelT1567 · Exfiltration Over Web Service

Analysis

The published tarball of this SDK carries an injected preinstall hook (`node lib/setup.mjs`) that loads an obfuscated 856 KB payload, `lib/Math_Symbol.js`. The payload sets a global marker (`globalThis.WORMTAG='tensrlake'`) and then harvests credentials from the installing machine: `~/.npmrc` and `.npmrc`, `~/.aws/credentials`, `~/.ssh/id_rsa` and `~/.ssh/authorized_keys`, `~/.git-credentials`, `~/.vault-token`, `~/.terraform.d/credentials.tfrc.json`, `~/.config/gcloud/credentials.db` and `application_default_credentials.json`, `/root/.kube/config`, `~/.config/solana/id.json`, `~/.foundry/keystores/*`, `~/.cosmos/config/priv_validator_key.json`, `~/.config/sui/sui_config/sui.keystore`, `~/.keplr/*`, `~/.electrum*/wallets/*`, `~/.config/Exodus/exodus.wallet/*`, `~/Library/Application Support/MetaMask/*`, `~/.ledger/config.json`, `~/.config/1Password/1password.sqlite`, `~/.local/share/keyrings/login.keyring`, Firefox `key4.db`, and a long list of AI/CI CLI config files (`~/.codex/config.toml`, `~/.gemini/config.json`, `~/.cursor/cli-config.json`, `~/.codeium/config.json`, `~/.continue/config.json`, `~/.circleci/cli.yml`, `~/.config/hardhat/config.json`). It also reads CI environment variables (GITHUB_TOKEN, GITHUB_WORKFLOW_REF, GITHUB_REPOSITORY, GITLAB_CI, CI, VAULT_TOKEN, VAULT_AUTH_TOKEN), uses the stolen npm token to enumerate the victim's published packages and scopes with write access, and uses the stolen GitHub token against api[.]github[.]com to fetch repository contents and commit/push files into the victim's own repositories — worm-style self-propagation. It writes `~/.ssh/authorized_keys` for persistence and fingerprints the host (hostname, username, OS, cwd, locale). The hook deliberately returns early when CI, GITHUB_ACTIONS or GITLAB_CI is set, so it stays dormant inside build pipelines and only executes on developer workstations. Transport endpoints observed: api[.]github[.]com and registry[.]npmjs[.]org, abused as the exfiltration and propagation channel; no attacker-owned C2 domain is present.

analyzed by
Leitwacht
first seen
Oct 8, 2026, 01:12 AM
analyzed
Oct 8, 2026, 11:03 AM
weekly installs
18,826

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.