tensorlake@0.5.144
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 10:42 AM UTC
OSV ID
MAL-2026-17650
Ecosystem
npm
Summary
The npm package tensorlake@0.5.144 ships lib/setup.mjs as a heavily obfuscated single-line script using hex-mangled identifiers (_0x15c964, _0x35672e,...), a transformation shape typical of hostile loader code rather than ordinary minification. Multiple shipped bundles under dist/ (dist/index.cjs, dist/applications/index.cjs, dist/sandbox-image.cjs, dist/function-agent/main.cjs, dist/function-executor/main.cjs, and their.js counterparts) combine require("child_process") with repeated POST request primitives and shell utilities such as curl and ping, including host/id-collection patterns alongside outbound HTTP calls. Automated contextual tracing of these files was blocked by the provider safety filter after the model engaged with the content, which is a pattern that correlates with hostile code rather than benign SDK traffic. The combination of an obfuscated setup script and child_process + hardcoded HTTP POST patterns in the shipped bundles is consistent with install-time or load-time execution of attacker-controlled behavior against the installer's host.
Source: amazon-inspector (898b31edaabc82c76dc8d25f10ceee38c7ef51ee34887461a5bc8ce9f0378b50)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.