[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fIrp8759jeTgIkou28hMvNRaenvwsOG1X58o5Fg0UxqY":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"5b7cb75a-4c13-4a0e-bb9b-cba9b89bdce4","compromised-npm-package-delivers-self-propagating-credential-stealing-worm","da5392f0-359e-4fe9-a137-bc66a6887b5a","Compromised npm Package Delivers Self-Propagating Credential-Stealing Worm","The tensorlake npm package was poisoned in a classic open-source supply chain attack, injecting a self-replicating worm (Shai-Hulud) that steals credentials, establishes persistence, and executes remote code on victim machines. What makes this attack particularly dangerous is the worm's ability to re-publish itself to npm, amplifying the blast radius far beyond the initial compromise. The use of an Ethereum smart contract for command-and-control (C2) communication is a novel evasion technique that makes traditional domain-based blocking ineffective. This incident underscores the implicit trust developers place in third-party packages and the catastrophic consequences when that trust is exploited.","**Immediate actions:**\n- Audit all projects for dependencies on `tensorlake` and remove or pin to a verified clean version immediately.\n- Rotate all credentials and secrets on any system that installed the compromised package version (0.5.144).\n- Revoke and regenerate npm publish tokens to prevent the worm from re-publishing under your account.\n\n**Long-term improvements:**\n- Implement a software composition analysis (SCA) tool in your CI\u002FCD pipeline to automatically flag newly published or updated packages with suspicious behavior.\n- Enforce npm package integrity checks using lockfiles (`package-lock.json`) and verify checksums before installation in production pipelines.\n- Adopt a private package registry or dependency mirroring strategy to control which package versions are permitted in your environment.\n\n**Detection measures:**\n- Monitor outbound network traffic for unusual destinations, including Ethereum RPC endpoints, which may indicate blockchain-based C2 communication.\n- Deploy endpoint detection tools that alert on unexpected process persistence mechanisms (e.g., new cron jobs, startup entries) created post-npm install.\n- Enable npm audit logging and integrate alerts for any automated package publish events originating from developer or CI\u002FCD accounts.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 16: Application Software Security","NIST SP 800-161: Supply Chain Risk Management Practices","NIST SP 800-53 SA-12: Supply Chain Protection","NIST SP 800-53 RA-5: Vulnerability Monitoring and Scanning","NIST SP 800-53 AU-12: Audit Record Generation","NIST Cybersecurity Framework DE.CM-3: Personnel Activity Monitoring","SLSA Framework: Supply Chain Levels for Software Artifacts (Level 3+)","OpenSSF Scorecard: Dependency Update Tool and Token Permissions checks","GDPR Article 32: Security of Processing (if EU user credentials were harvested)","published","2026-10-08T08:21:10.675252+00:00","2026-10-08T08:21:10.572+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F10\u002Ftensorlake-npm-package-compromised-to.html","tensorlake-npm-package-compromised-to-deliver-shai-hulud-credential-stealing-wor-a94793","Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":37,"name":38,"slug":39,"description":40,"color":41},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":43,"name":44,"slug":45,"description":46,"color":47},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[49],{"id":50,"date":51,"edition":52,"title":53,"audio_url":54},"ad9ad71a-ab06-4a6e-a172-192c16d068ed","2026-10-08","afternoon","ThreatNoir Afternoon Brief — October 8","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-10-08\u002Fthreatnoir-afternoon-brief-2026-10-08.mp3"]