Malicious Tensorlake npm Release
The malicious Tensorlake npm release requires containment first, followed by evidence-led cleanup and prompt credential rotation.
Tensorlake’s project says malicious tensorlake@0.5.144 was published after a repository-administrator account committed the payload directly to main and manually dispatched the project’s release workflow. The project says npm removed 0.5.144.
The release carried valid Sigstore provenance. BlackTree analysis: provenance identifies a source and build path. It does not certify that the source was benign.
Read the registry snapshot precisely
At 13:26:53 CEST on 8 October, npm registry metadata still marked 0.5.143 as latest. It preserved the 0.5.144 publication time, 01:12:07.320 UTC, but exposed no version object for 0.5.144 or 0.5.145 and no 0.5.145 time entry.
A repository bump to 0.5.145 is not evidence that npm users can install it.
BlackTree recommends checking the registry again before selecting a recovery version. The captured state does not make 0.5.143 universally safe; it only establishes the latest tag and absent version objects at one observation time.
Establish what actually ran
Researchers traced the preinstall hook through setup.mjs to Math_Symbol.js and identified credential-theft, propagation and persistence capabilities. Capability is not proof of execution or theft on every installation.
The loader skips CI=true or 1, GITHUB_ACTIONS=true, GITLAB_CI=true and RUNNER_ENVIRONMENT=github-hosted. A lockfile or CI inventory hit is therefore exposure evidence, not proof that the payload ran.
Do not rotate blindly
SafeDep says the deletion watcher arms only when a stolen-token account has no organisations. If present, it can react destructively when that applicable GitHub token is rejected.
BlackTree recommends this conditional sequence:
- Isolate the affected endpoint. Preserve volatile, file, process, network and account evidence before cleanup where operationally safe.
- Establish execution. Confirm execution and identify any installed monitor and trapped token.
- Remove the specific trap. If the monitor is present, eradicate it safely before invalidating that applicable GitHub token. Do not copy destructive shell commands from third-party reports.
- Rotate promptly from a clean system. Rotate exposed credentials from a clean system, then review repositories and package activity.
- Rebuild when assurance is weak. Restore from known-good sources and verify that persistence, altered workflows and unexpected repository files are gone.
This is not permission to leave every exposed token valid. The sequencing applies only after containment and only where the relevant monitor is present.
Keep maintainer and consumer work separate
The project reverted to clean commit 52f19c8a, added install-script guards and tightened repository review controls. Its remaining administrator work included securing the compromised account, revoking its sessions, personal access tokens and keys, rotating release-workflow secrets and removing six tensorlake-native-*@0.5.144 artifacts before a clean publish.
Those are project-owner actions, not steps a package consumer can complete. Endor found no install script or payload in the six native packages. Their planned removal does not prove that they carried the malicious JavaScript.
What the evidence does not establish
There is no verified victim, installation, execution, stolen-credential, propagation or downstream-compromise count. Download totals would not supply one. The evidence also does not establish an actor identity, a CVE or successful compromise on every system that resolved the package.
Related BlackTree context
This incident is distinct from ChainDrop’s trusted-publishing compromise and the earlier case where valid provenance accompanied malware published by an exposed workflow. They explain the trust lesson, but neither closes the Tensorlake response question.
Sources and publication details
- Tensorlake pull request 1016. Created and merged 8 October 2026.
- npm registry metadata for Tensorlake. Observed 8 October 2026 at 13:26:53 CEST.
- Endor Labs, Aikido, SafeDep and StepSecurity. Dated 8 October 2026; clocks not shown.


