HomeAIAI Agent Security: A Hijacked SDK Goes After Agent Keys as Copilot,...

AI Agent Security: A Hijacked SDK Goes After Agent Keys as Copilot, Bitdefender and Citadel Add Guardrails

AI coding agents are now worth attacking for what they hold: tokens, cloud keys and the configuration files that tell them which tools to trust. This week brought a clear example and a run of new defences.

  • tensorlake, a software development kit (SDK) on npm, the main JavaScript package registry, shipped a malicious version that steals credentials and AI-tool settings and spreads itself (confirmed by StepSecurity and Socket) [1][2].
  • GitHub made local sandboxing for Copilot generally available, built on Microsoft’s Execution Containers (confirmed) [3].
  • Bitdefender released AI Guardian, a free beta for macOS that checks each action an agent takes (confirmed) [4].
  • Citadel AI opened early access to Radar for Agents, which tracks what agents exist and what they do (confirmed) [5].
  • LangChain and past.dev shipped agent tooling that decides what an agent can see before it runs (confirmed launches; past.dev’s benchmark score is the company’s own) [6][7].

No attack steps, payloads or clean-up commands appear below.

What happened to tensorlake?

Tensorlake makes cloud services and sandboxes for AI applications; its npm package is the TypeScript SDK for them [2]. According to StepSecurity, someone pushed malicious files straight to the main branch of the project’s GitHub repository under a maintainer’s name, starting at 02:20 BST on 7 October, with no pull request. The project’s own release workflow then published version 0.5.144 to npm at 02:12 BST on 8 October [1].

Because the release was built from the real repository, npm showed a valid provenance attestation for it. StepSecurity’s point is blunt: an attestation “says where a package was built. It doesn’t say the code is safe” [1].

The malware runs when the package is installed and skips itself on build servers, so developers’ own machines are the target [1]. StepSecurity and Socket (as reported by The Hacker News) say it collects GitHub and npm tokens, cloud keys, Kubernetes and Vault secrets, SSH keys, saved browser logins, and configuration files for AI tools including Claude, Cursor and Windsurf; Socket’s list adds Kiro and Zed and their MCP settings [1][2]. With stolen tokens it republishes the victim’s own packages with itself inside, and writes Claude Code and VS Code settings files into the victim’s repositories so it runs again when someone opens the project [1][2]. Researchers link it to the “Shai-Hulud” family of npm worms [2].

Why does the order of the clean-up matter?

The nasty twist is what StepSecurity calls a “hostage token”. When the malware has a GitHub token, it installs a background watcher that keeps checking whether the token still works. If the victim revokes it, the watcher deletes the user’s home folder [1]. Socket describes the same mechanism as running attacker-supplied code that is likely destructive [2].

So the obvious first move after a breach, revoking the stolen token, is the one that triggers the damage. StepSecurity’s advisory sets out the safe order: deal with the watcher first, then rotate credentials [1]. Anyone who installed 0.5.144 should follow that published guidance, or their security team’s, step by step, and not revoke tokens first. StepSecurity says to pin the previous version, 0.5.143 [1].

The sources differ on one point. StepSecurity said 0.5.144 could still be downloaded when it checked; The Hacker News, citing Socket, says it is no longer available [1][2].

What did GitHub ship?

On 7 October GitHub made local sandboxing for Copilot generally available in Copilot CLI, the Copilot app and VS Code sessions using Agent Host [3]. Commands and tools that Copilot starts on a developer’s own machine run with restricted access to files, the network, Git and GitHub credentials, according to a policy set by the developer or their organisation [3].

It is powered by Microsoft Execution Containers (MXC), which turn one sandbox policy into native controls on Windows, macOS and Linux [3]. Enterprises can require sandboxing and “enforce policies that developers cannot weaken” [3]. GitHub adds that the policy applies to tool execution “regardless of which model Copilot uses” [3]. It costs nothing extra.

What are Bitdefender and Citadel offering?

Bitdefender AI Guardian sits between an agent and the files, tools and credentials it tries to use. Each action gets a verdict as it happens: allowed, flagged for review or blocked [4]. The free open beta runs on macOS and supports Claude Code 2.1.121 or newer and OpenClaw 2026.6.6 or newer. Bitdefender says prompt analysis stays on the Mac, though some checks, such as web address reputation, use its cloud [4]. It also says plainly that “no security product guarantees complete protection” [4].

Citadel AI aims at larger organisations. Radar for Agents builds a register of the agents and tools (including MCP servers) in use, checks for excessive permissions, and watches sessions at run time [5]. It judges each action in light of who is running the agent, what they asked for and what it has done so far, to catch “intent drift”, where an agent wanders from its task [5]. It covers Copilot, Claude and Dify, and is available through an early access programme [5].

What did LangChain and past.dev release?

Neither is a security product, but both build access limits into the plumbing.

LangChain’s Managed Deep Agents v0.9, in public beta, lets an agent set its own reminders and recurring tasks from a conversation. Each schedule runs as the person who asked, with their permissions [6]. A single deployment can also pick its model, instructions, skills, MCP servers and sandbox at the start of each run, so one agent can serve several teams. Because this is set before the model runs, LangChain says, the agent “never sees skills or MCP tools outside its configuration”, which “doubles as access control” [6].

past.dev launched a memory service for agents on 6 October. Each stored fact keeps the date it became true, what it replaced and its source, and each person sees only what they are allowed to [7]. The company claims 85.03% on the BEAM memory benchmark at 10 million tokens, against a previous best published result of 68.0% [7]. That is past.dev’s own figure; it has published its evaluation code so others can check [7].

What links these stories?

The tensorlake worm went after exactly what agents carry: tokens, keys and tool settings. The defences all try to limit what an agent, or anything running alongside it, can reach, using rules outside the model: an operating-system sandbox, a per-action check, a register of who can do what, or a configuration fixed before the run starts.

What this does not prove

  • How many developers installed tensorlake 0.5.144. Neither StepSecurity nor Socket gives a figure [1][2].
  • That a sandbox would have stopped the worm. Copilot’s sandbox limits commands Copilot runs; tensorlake ran when a developer installed a package [1][3].
  • That AI Guardian or Radar catch real attacks. Neither company cites independent tests; Citadel’s product is in early access and Bitdefender’s is a beta [4][5].
  • past.dev’s lead on BEAM. It is a company-reported score. Its release also gives two different sets of “previous best” figures for the smaller history sizes; only the 10-million-token comparison is consistent [7].

The Bottom Line

The tensorlake hijack shows why agent security now starts on the developer’s laptop: the package came from the real project, carried a valid build record and went straight for AI-tool keys [1]. If you installed it, follow StepSecurity’s published order and do not revoke tokens first [1]. The week’s new guardrails, from GitHub’s sandbox to Bitdefender’s action checks and Citadel’s monitoring, all share one idea: decide what an agent may touch before it acts, and enforce it outside the model [3][4][5].

Related on TSN: Fences for AI Agents: Microsoft’s Execution Containers and AWS’s Strands Box · MCP Explained: The USB-C for AI Tools · It Sounds Like It Remembers

Sources

  1. Ashish Kurmi, “Tensorlake npm Package Compromised: A Worm With a Hostage Token That Wipes Your Machine If You Revoke It,” StepSecurity blog, 8 October 2026. https://www.stepsecurity.io/blog/tensorlake-npm-compromised-hostage-token-worm
  2. Ravie Lakshmanan, “Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm,” The Hacker News, 8 October 2026 (quoting Socket). https://thehackernews.com/2026/10/tensorlake-npm-package-compromised-to.html
  3. GitHub, “Local sandboxing for GitHub Copilot now generally available,” GitHub Changelog, 7 October 2026. https://github.blog/changelog/2026-10-07-local-sandboxing-for-github-copilot-now-generally-available/
  4. Alina Bîzgă, “Introducing Bitdefender AI Guardian: Free Security for AI Agents,” Bitdefender HotForSecurity blog, 7 October 2026. https://www.bitdefender.com/en-us/blog/hotforsecurity/bitdefender-ai-guardian-free-security-for-ai-agents
  5. Citadel AI, “Announcing Citadel Radar for Agents: Cross-Platform Agent Control and Visibility,” news release, 7 October 2026. https://citadel-ai.com/news/2026/10/07/citadel-radar-for-agents/
  6. Nathan Drezner, “Managed Deep Agents v0.9: schedules, per-run configuration, and Slack reactions,” LangChain blog, 7 October 2026. https://www.langchain.com/blog/managed-deep-agents-schedules-per-run-configuration-slack
  7. past.dev, “past.dev Introduces Frontier Memory for AI Agents: #1 on BEAM, the Largest Public Memory Benchmark,” press release via PR Newswire, 6 October 2026. https://www.prnewswire.com/news-releases/pastdev-introduces-frontier-memory-for-ai-agents-1-on-beam-the-largest-public-memory-benchmark-302899770.html

Source note: StepSecurity’s advisory includes step-by-step clean-up commands and indicators of compromise; per TSN policy none are reproduced here, and readers are pointed to the advisory itself. Times converted from UTC (StepSecurity gives 01:20 UTC on 7 October and 01:12 UTC on 8 October). StepSecurity sells supply-chain security tools and Socket is a security vendor. past.dev’s release states two different “previous best” sets for the 100K to 1M sizes (76.9/71.1/75.0 in its summary, 86.2/80.1/79.1 in its table); only the 10M comparison (68.0%) matches in both, so only that is used.

Share this story

More in this category

Latest on TSN

Free TSN tools: crypto calculator, Flux dashboard and more.