Tensorlake npm package compromised, steals developer credentials
Tensorlake npm package v0.5.144 shipped a credential-harvesting worm that self-propagates via stolen npm tokens. The malicious version ran Oct 7-8 before registry removal. It exfiltrated GitHub PATs, AWS credentials, Vault tokens, SSH keys, and AI tool configs. The worm republished compromised versions of victim-maintained packages with Sigstore provenance, creating second-order supply chain risk.
Separately, attackers hijacked Ghana, Sierra Leone, and American Samoa DNS registries to obtain 12 unauthorized Google certificates from Let's Encrypt and ZeroSSL.
In this issue:
- Tensorlake npm v0.5.144: credential worm with npm token propagation
- DNS registry hijack: 12 unauthorized Google certs via .gh, .sl, .as
- Qualcomm QPaCE: hardware LZ4 compression for ZRAM on Snapdragon 8 Elite Gen 6
- AMD Zen 6 IBS Memory Profiler: hardware sampling for CXL tiered memory
Tensorlake npm Package Delivered Credential-Stealing Worm
The Signal
tensorlake npm package v0.5.144 shipped obfuscated malware harvesting CI/CD secrets and self-propagating via victim npm tokens.
What Changed
- Malicious version pushed to main branch Oct 7, published Oct 8, removed from registry Oct 8.
- Preinstall hook executes `package/lib/setup.mjs`, launches obfuscated loader via Bun runtime.
- Harvests npm tokens, GitHub tokens, AWS credentials, Vault, Kubernetes configs, SSH keys, .env files.
- Deploys HackBrowserData binary to steal browser credentials and cryptocurrency wallets.
- Worm enumerates victim's npm packages, builds Sigstore provenance, republishes compromised versions.
- Targets AI tool configs: Claude, Cursor, Kiro, Windsurf, Zed MCP files.
- Uses Ethereum contract for C2 resolution, GitHub repo named "Shai-Hulud: Here We Go Again" for exfil.
- PowerShell monitor polls `api.github.com/user`, executes destructive payload if token revoked.
Operational Impact
Teams that installed 0.5.144 must rotate all credentials accessible to affected environments immediately—npm tokens, GitHub PATs, cloud credentials, and SSH keys. The worm self-propagates by publishing malicious updates to packages the victim maintains, creating second-order supply chain risk. Check CI/CD logs for connections to `iseekaigogo[.]com` and review GitHub repos for unexpected `.claude/settings.json` or `.vscode/tasks.json` commits. Any GitHub token exposed to the malware should be treated as compromised even after revocation due to the hostage token mechanism.
Watch For
Scan CI/CD workflow runs between Oct 7-8 for unexpected Bun runtime execution or network calls to the C2 domain. Projects downstream of any package published by compromised npm identities during this window require audit.
Attackers Hijack .gh, .sl, .as DNS Registries for Google Certificates
The Signal
Attackers compromised Ghana, Sierra Leone, and American Samoa DNS registries to obtain 12 unauthorized certificates for Google domains.
What Changed
- Attackers modified authoritative DNS for .gh, .sl, .as ccTLDs between September 22-27, 2026.
- Let's Encrypt issued 11 certificates, ZeroSSL issued 1, all via domain validation checks. https://community.letsencrypt.org/t/certificates-for-google-and-youtube-were-issued-and-have-been-revoked/21000
- Targeted domains included `google.com.gh`, `*.google.sl`, `youtube.as` and wildcard variants.
- Google deployed CRLSets in Chrome to block certificates before CA revocation completed.
- Revocation lag ranged from 1.5 days to 6 days after Certificate Transparency logging.
Operational Impact
Domain validation fails when DNS is compromised at the registry level. CAs can reuse validation checks for up to 200 days under current Baseline Requirements, meaning attackers could request additional certificates after regaining DNS control. Teams must monitor Certificate Transparency logs for all owned domains, including parked and regional ccTLD variants. Deploy strict CAA records with `accounturi` parameters to limit issuance to your CA account. File Certificate Problem Reports with the issuing CA for any unauthorized certificates.
Watch For
Baseline Requirements will reduce validation reuse windows to 100 days in March 2027 and 10 days in March 2029. Google indicated other global brands were affected but did not disclose names or confirm whether certificates were used in active attacks.
Qualcomm QPaCE Accelerates ZRAM on Snapdragon 8 Elite Gen 6
The Signal Qualcomm posted Linux patches for QPaCE, a hardware compression block in Snapdragon 8 Elite Gen 6 SoCs.
What Changed
- QPaCE accelerates page compression/decompression for ZRAM block devices using LZ4.
- New qpace-lz4 Zcomp backend added for hardware-accelerated compression operations.
- Initial driver implements synchronous single-page "urgent" path for low-latency operations only.
- Hardware supports ring-based async batch compression; driver does not yet implement it.
- Device tree support currently limited to Snapdragon 8 Elite Gen 6 "Hawi" SoC. Patch series.
Operational Impact Mobile and embedded Linux systems using ZRAM for compressed swap will see faster compression on supported Qualcomm hardware versus software LZ4. Current driver latency optimizes for single-page operations but leaves high-throughput batch workloads on the table until async support lands. Teams evaluating this for memory-constrained Android or embedded devices should test with realistic swap patterns.
Watch For Async batch compression patches will determine whether QPaCE delivers meaningful throughput gains for heavy swap scenarios. Unclear if older Snapdragon SoCs will receive backported hardware support or driver compatibility.
AMD Zen 6 IBS Memory Profiler Enables Hardware-Assisted Hot Page Detection
The Signal
AMD Zen 6 adds IBS Memory Profiler for lightweight hardware sampling of memory access patterns.
What Changed
- IBS Memory Profiler provides per-access profiling with virtual/physical address tracking and NUMA node data.
- Designed for integration with Linux pghot subsystem patches for hot page promotion.
- Targets tiered memory deployments combining DRAM and CXL-based memory on EPYC servers.
- Benchmarks on 256-core EPYC Venice show low overhead when engaged via pghot.
- Presentation materials available from Linux Plumbers Conference 2026.
Operational Impact
Teams running EPYC servers with CXL memory tiers gain CPU-level sampling for identifying frequently accessed pages. This shifts hot page detection from purely software heuristics to hardware-assisted profiling. The pghot subsystem remains under development and not yet in mainline, so production use depends on future kernel releases.
Watch For
Track pghot patch progression toward mainline Linux. The work aims for vendor-neutral CPU sampling interfaces that extend beyond AMD hardware.
Quick Reads
- Tensorlake — Malicious npm package v0.5.144 stole credentials and self-propagated via victim tokens.
- DNS Registries — Attackers hijacked .gh, .sl, .as registries to obtain unauthorized Google domain certificates.
- Qualcomm QPaCE — New hardware accelerator speeds ZRAM compression on Snapdragon 8 Elite Gen 6.
- AMD Zen 6 — IBS Memory Profiler enables hardware-assisted hot page detection for tiered memory.
Subscribe to Signal Field
Data & infrastructure news. Subscribers get new posts by email a day before they go live on the site.
Email signup is coming soon — in the meantime, follow the Signal Field RSS feed.