StepSecurity, a security vendor, says [email protected] steals credentials on install and, if you revoke the GitHub token it stole, deletes the home directory or the Windows user profile. Ashish Kurmi filed it on 8 October: GitHub issue 1014. The issue is a report to the project, not a maintainer’s account of how the login was used.
What StepSecurity says the install did
StepSecurity says the preinstall hook runs setup.mjs, skips itself on CI, downloads Bun, and runs an obfuscated 856 KB file, which the vendor says it decoded without executing. The credentials it lists include GitHub and npm tokens, cloud keys, Kubernetes and Vault secrets, SSH keys, browser logins, and config for Claude, Cursor, and Windsurf. The vendor says that data is encrypted and sent to a public repo described as “Shai-Hulud: Here We Go Again,” or to iseekaigogo.com. A stolen npm token republishes the victim’s packages. A stolen GitHub token commits .claude and .vscode files as [email protected] with the message “chore: update dependencies”. A service named gh-token-monitor checks that token every 60 seconds for up to 24 hours and, if GitHub rejects it, deletes the home directory or the Windows user profile.
A provenance attestation is a build record
StepSecurity says the files were pushed straight to main on tensorlakeai/tensorlake under a maintainer’s name, starting at 01:20 UTC on 7 October, with seven more commits and no pull request. At 01:12 UTC on 8 October the release workflow published 0.5.144 under the same identity, and the npm files matched main. On the attestation, StepSecurity writes: “The attestation says where a package was built. It doesn’t say the code is safe.” How the account was used is not established there.
Pull request 1016, opened and merged by the GitHub account diptanu at 04:32 UTC, says a repo-admin account committed the payload through the GitHub web UI and a manual workflow dispatch signed it with Sigstore. The text says locking “the compromised GitHub account” was still to do. That wording is the pull request’s, not a finding that a named person acted on purpose.
Those files are a persistence spot. A Claude Code SessionStart hook runs when a session starts, and a VS Code folderOpen task runs when a folder opens. A commit carries both into the next clone.
What to do, in StepSecurity’s order
Do not revoke a GitHub token until the monitor is gone. Check npm ls tensorlake, lockfiles, and any clone of main since 7 October if you ran npm install in typescript/. Pin [email protected], delete node_modules, and run npm cache clean --force. ignore-scripts=true stops install hooks.
Then remove the monitor. Back up first. Look for ~/.config/gh-token-monitor/. On Linux, disable the user unit gh-token-monitor.service and remove that folder, ~/.local/bin/gh-token-monitor.sh, and the unit file. On macOS, boot out the LaunchAgents plist and remove those files. On Windows, delete the Task Scheduler logon task that runs monitor.ps1.
Only then revoke the GitHub token and rotate npm tokens, cloud keys, SSH keys, Kubernetes and Vault credentials, .env secrets, AI tool keys, and browser passwords. Look for the Shai-Hulud description, the noreply author, and hook files you did not add. If the machine may still be dirty, wipe it. On CI, StepSecurity says the hook skips itself; rotate secrets that job could see.
Status as of Thursday morning UTC
StepSecurity wrote that 0.5.144 was still downloadable when it checked. At 05:57 UTC on Thursday 8 October 2026, the npm registry showed latest as 0.5.143, with 0.5.144 gone and 0.5.145, the bump in pull request 1016, unpublished. time.modified was 02:54 UTC.
Six tensorlake-native 0.5.144 packages named in the pull request were still up: macOS arm64, Windows x64, and Linux x64 and arm64 for both gnu and musl. The pull request says they still needed to be unpublished. Issue 1014 was open. The repo’s public advisory list had no entry for this release.

The Campfire
No commentsNobody has pulled up a log by this one yet. Be the first to say what you make of it.
Held for the desk. It appears after a look.