Eigen RadarAI
Analysis

Tensorlake’s malicious installation code targets developer credentials

Tensorlake’s 0.5.144 release contains malicious code that runs during installation and searches for developer credentials. Sonatype identified paths for sending collected data through GitHub and changing repository files. Its investigation distinguishes those capabilities from confirmed compromise of downstream systems. Removing a package leaves the question of whether its installation code already ran unresolved.

Artificial Intelligence··Morning
A disconnected security key and network cable beside a laptop

Malicious code runs before installation finishes

Tensorlake’s TypeScript software development kit contained malicious installation code in release 0.5.144. The package normally supports work with isolated computing environments, repositories and cloud services. Its compromised release targets developer credentials available to the installation process.[1], [2]

A preinstall hook starts concealed JavaScript through Bun, a tool for running that programming language. The payload can download Bun when it is absent and accept commands from a remote system. Installation therefore supplies an execution point before normal use of the package begins.[1]

GitHub access opens another route for collected data

Sonatype’s security researchers found a fallback route that uses stolen GitHub access to create a public repository and commit collected information. GitHub is a service for hosting and collaborating on code. The malware can also add Claude and VS Code configuration files to repositories it can reach. These are capabilities identified in the code; publication of stolen data and changes to downstream repositories have not yet been confirmed.[1]

Some automated build environments stop the loader

The loader exits on encountering several markers used by continuous-integration systems, which automatically build and check software changes. Other GitHub Actions logic remains in the payload, with its role still under investigation. Removing the release from the npm package registry does not erase copies already installed, and deleting the package does not invalidate credentials that its code may have read.[1]

References

  1. News sourceSonatypeTensorlake’s malicious release targets developer credentials during installation↩1↩2↩3↩4
  2. News sourceEndor LabsTensorlake’s 0.5.144 release carries malicious installation code↩