This week's roundup from SecurityWeek is a useful snapshot of where attacker tradecraft is heading in 2026: upstream developer tooling as an intrusion vector, AI-assisted targeting of financial institutions in South Korea, a botnet that receives tasking through poem-shaped content, and operational telemetry leaking from internet-exposed NVIDIA GPU monitoring endpoints. None of these stories alone defines a campaign — but together they describe the environment your SOC is actually operating in. Two of them are immediately actionable from a detection engineering standpoint: the Tensorlake npm SDK compromise (a classic package-repository supply chain event) and exposed NVIDIA GPU monitors leaking telemetry (a classic shadow-inventory failure). This post breaks down each threat from a defender's perspective and gives you concrete hunting content you can deploy today.
Technical Analysis
1. Tensorlake npm SDK Compromise — Supply Chain Intrusion via Developer Tooling
The Tensorlake npm SDK was compromised, meaning that developers and CI/CD pipelines pulling the poisoned package version executed attacker-controlled code at install or runtime. No CVE has been assigned to this event as of publication — this is a package integrity compromise, not a software vulnerability, and it should be treated accordingly.
The typical attack chain for a malicious npm package:
- Distribution: Attacker publishes a malicious version to npm (via compromised maintainer credentials, token theft, or account takeover).
- Execution:
npm installtriggers lifecycle scripts (preinstall,install,postinstall) defined inpackage.json. These run with the privileges of the installing user — often a developer workstation or a CI runner holding cloud credentials, signing keys, and registry tokens. - Payload staging: Malicious lifecycle scripts commonly spawn
node,curl/wget, or shell interpreters to fetch second-stage payloads, harvest environment variables (CI secrets live in environment variables — this is the primary prize), and enumerate~/.npmrc,~/.aws,~/.ssh, and kubeconfigs. - Persistence / exfiltration: Stolen tokens are exfiltrated to attacker infrastructure, often over HTTPS to domains with low reputation scores.
Why this matters more than a typical endpoint compromise: CI/CD runners are credential concentrators. A poisoned package executed in a build pipeline can expose signing keys, cloud IAM credentials, and downstream registry publishing tokens — turning one compromised SDK into a repeatable supply chain launchpad.
2. AI-Assisted Breaches of South Korean Banks
Reporting indicates threat actors leveraged AI tooling in intrusions against South Korean banking institutions — accelerating reconnaissance, social engineering content generation, and potentially malware iteration. The defensive takeaway is not that AI introduces a novel exploit class; it compresses attacker timelines. Phishing lures are better localized, reconnaissance is faster, and the window between initial access and objective completion shrinks. If your detection content assumes slow, noisy attacker behavior, recalibrate your dwell-time assumptions.
3. Poem-Guided Botnet C2
A botnet was observed receiving tasking embedded in poem-shaped content — a steganographic / dead-drop C2 technique where instructions are encoded in publicly posted text. This is a known pattern (attackers have used social media posts, GitHub gists, and forum comments as dead drops for years), but it defeats naive domain-reputation and C2-signature detection because the command channel looks like benign content on legitimate platforms. Defense hinges on behavioral analytics: endpoints making periodic, low-volume requests to content platforms at fixed intervals, followed by execution activity, are the tell.
4. Exposed NVIDIA GPU Monitors Leaking Telemetry
Internet-exposed NVIDIA GPU monitoring endpoints — typically Prometheus exporters such as dcgm-exporter (default port 9400) and nvidia_gpu_exporter, or DCGM's own interfaces — are leaking telemetry. GPU telemetry sounds benign until you consider what it reveals: model names and driver versions (vulnerability targeting), utilization patterns that fingerprint AI/ML workloads and tenant activity, hostnames and job metadata embedded in exporter labels, and in some configurations process-level GPU usage. For organizations running AI infrastructure, this is reconnaissance gold for an attacker deciding which targets are worth the effort. It also maps your expensive compute estate for cryptojacking and resource-theft actors.
Exploitation status: No CVE applies here — this is a misconfiguration class. Shodan/Censys exposure of exporter ports is observable today, and opportunistic scanning of Prometheus exporters is continuous. Treat as active risk.
Detection & Response
Sigma Rules
The following rules target the two most detectable behaviors from this roundup: malicious npm lifecycle script execution (supply chain compromise) and post-exploitation patterns consistent with AI-accelerated intrusions (credential file access from scripting interpreters). A third rule covers suspicious outbound access to Prometheus exporter ports from unexpected sources, useful for detecting internal reconnaissance against GPU infrastructure.
---
title: Suspicious npm Lifecycle Script Execution
id: 3f8a2c71-9b4e-4d6a-ae12-7c5f9d2e8a41
status: experimental
description: Detects npm/node spawning shell interpreters, downloaders, or script engines during package install — consistent with malicious preinstall/postinstall lifecycle scripts in compromised npm packages such as the Tensorlake SDK incident.
references:
- https://www.securityweek.com/in-other-news-ai-used-in-korean-bank-breaches-poem-guided-botnet-empire-admin-gets-40-years/
- https://attack.mitre.org/techniques/T1195/001/
author: Security Arsenal
date: 2026/04/06
tags:
- attack.initial_access
- attack.t1195.001
- attack.execution
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith:
- '\node.exe'
- '\npm.cmd'
- '\npm.exe'
- '\npx.cmd'
- '\pnpm.exe'
- '\yarn.exe'
selection_child:
Image|endswith:
- '\cmd.exe'
- '\powershell.exe'
- '\pwsh.exe'
- '\wscript.exe'
- '\cscript.exe'
- '\mshta.exe'
- '\curl.exe'
- '\certutil.exe'
condition: selection_parent and selection_child
falsepositives:
- Legitimate packages with native build steps (node-gyp) may spawn cmd.exe; tune by package allowlist in build environments
level: high
---
title: Scripting Interpreter Accessing Credential Stores
id: 8b2e4f16-1c7a-4d93-bf28-5e9a3c7d1f62
status: experimental
description: Detects node, python, or shell interpreters reading cloud credentials, npm tokens, or SSH keys — a hallmark of malicious package payload behavior harvesting CI/CD secrets.
references:
- https://www.securityweek.com/in-other-news-ai-used-in-korean-bank-breaches-poem-guided-botnet-empire-admin-gets-40-years/
- https://attack.mitre.org/techniques/T1552/001/
author: Security Arsenal
date: 2026/04/06
tags:
- attack.credential_access
- attack.t1552.001
logsource:
category: process_creation
product: linux
detection:
selection_img:
Image|endswith:
- '/node'
- '/python'
- '/python3'
- '/sh'
- '/bash'
selection_cmd:
CommandLine|contains:
- '.npmrc'
- '.aws/credentials'
- '.ssh/id_'
- '.kube/config'
- 'gcloud/config'
- 'azure/accessTokens'
condition: selection_img and selection_cmd
falsepositives:
- Developer tooling legitimately reading configs; investigate source package and parent process tree before dismissing
level: high
---
title: Internal Reconnaissance Against Prometheus GPU Exporter Port
id: 5d1a9c83-2e6f-4b48-ac39-8f4b6e2d7a15
status: experimental
description: Detects network connections to NVIDIA DCGM/GPU exporter port 9400 from hosts that are not designated monitoring scrapers — indicative of an attacker enumerating GPU infrastructure after initial access.
references:
- https://www.securityweek.com/in-other-news-ai-used-in-korean-bank-breaches-poem-guided-botnet-empire-admin-gets-40-years/
- https://attack.mitre.org/techniques/T1046/
author: Security Arsenal
date: 2026/04/06
tags:
- attack.discovery
- attack.t1046
logsource:
category: network_connection
product: windows
detection:
selection:
DestinationPort: 9400
filter_known_scrapers:
SourceIp:
- '10.0.0.0/8_PLACEHOLDER_REPLACE_WITH_YOUR_PROMETHEUS_IPS'
condition: selection and not 1 of filter_known_scrapers*
falsepositives:
- Prometheus/Grafana scrapers; replace the placeholder filter with your actual monitoring subnet before deployment
level: medium
KQL — Microsoft Sentinel / Defender
This hunt targets malicious npm lifecycle execution and credential harvesting on endpoints, plus external connections to GPU exporter telemetry ports (via firewall/CEF ingestion). Scope the time window to the period in which the compromised Tensorlake SDK version was available in your environment's dependency lockfiles.
// Hunt 1: Package manager spawning shells/downloaders (supply chain execution)
let lookback = 14d;
DeviceProcessEvents
| where Timestamp > ago(lookback)
| where InitiatingProcessFileName in~ ("node.exe", "npm.cmd", "npm.exe", "npx.cmd", "pnpm.exe", "yarn.exe", "node")
| where FileName in~ ("cmd.exe", "powershell.exe", "pwsh.exe", "curl.exe", "wget", "sh", "bash", "mshta.exe", "certutil.exe")
| project Timestamp, DeviceName, InitiatingProcessCommandLine, FileName, ProcessCommandLine, AccountName, InitiatingProcessParentFileName
| order by Timestamp desc;
// Hunt 2: Script interpreters touching credential artifacts (CI secret theft)
DeviceProcessEvents
| where Timestamp > ago(lookback)
| where FileName in~ ("node", "node.exe", "python", "python.exe", "bash", "sh")
| where ProcessCommandLine has_any (".npmrc", ".aws/credentials", ".ssh/id_", ".kube/config", "accessTokens")
| project Timestamp, DeviceName, FileName, ProcessCommandLine, InitiatingProcessFileName, InitiatingProcessCommandLine, AccountName;
// Hunt 3: Inbound/external connections to NVIDIA GPU exporter port 9400 (telemetry exposure check)
CommonSecurityLog
| where Timestamp > ago(lookback)
| where DestinationPort == 9400
| where not(SourceIP startswith "10." or SourceIP startswith "192.168." or SourceIP startswith "172.")
| summarize ConnectionCount = count(), Sources = make_set(SourceIP) by DestinationIP, DestinationHostName
| order by ConnectionCount desc;
Velociraptor VQL
Use this artifact to sweep endpoints and build hosts for package-manager-spawned child processes and for evidence of credential-store access patterns. Run it against developer workstations and CI runners first — those are the highest-value exposure points for a poisoned SDK.
-- Hunt for npm/node spawning suspicious child processes or touching credential stores
SELECT Pid,
Ppid,
Name,
Exe,
CommandLine,
Username,
CreateTime
FROM pslist()
WHERE (
CommandLine =~ '(?i)\.npmrc|\.aws/credentials|\.ssh/id_|\.kube/config|accessTokens'
AND Name =~ '(?i)node|python|bash|sh'
)
OR (
Name =~ '(?i)cmd\.exe|powershell|pwsh|curl|wget|mshta|certutil|bash|sh'
AND Ppid IN (
SELECT Pid FROM pslist()
WHERE Name =~ '(?i)node|npm|npx|pnpm|yarn'
)
)
Remediation & Verification Script
The script below (a) audits installed dependencies for the Tensorlake SDK and flags it for review, (b) enumerates packages with install lifecycle scripts across your project tree (the execution vector), and (c) checks whether NVIDIA exporter port 9400 is listening and whether it's bound to a public interface. Run it on developer workstations, build agents, and GPU hosts.
#!/usr/bin/env bash
# Security Arsenal — Tensorlake npm SDK + GPU exporter exposure audit
# Run on dev workstations, CI runners, and GPU hosts.
set -euo pipefail
echo "=== [1/4] Checking for Tensorlake SDK presence ==="
if npm ls -g 2>/dev/null | grep -i tensorlake; then
echo "[ALERT] Tensorlake SDK found globally. Verify version against the vendor/security advisory and remove if affected."
fi
find . -maxdepth 4 -name "package.json" -exec grep -l -i "tensorlake" {} \; 2>/dev/null | while read -r f; do
echo "[ALERT] Tensorlake referenced in: $f"
done
find . -maxdepth 5 -name "package-lock.json" -o -name "yarn.lock" -o -name "pnpm-lock.yaml" 2>/dev/null | while read -r lock; do
if grep -qi "tensorlake" "$lock"; then
echo "[ALERT] Tensorlake in lockfile: $lock — pin to a known-good version or remove."
fi
done
echo "=== [2/4] Enumerating packages with install lifecycle scripts (execution vector) ==="
if [ -d node_modules ]; then
grep -rl --include="package.json" -E '"(preinstall|install|postinstall)"' node_modules 2>/dev/null \
| head -50 | while read -r pkg; do
echo " [REVIEW] Lifecycle script present: $pkg"
grep -E '"(preinstall|install|postinstall)"' "$pkg" || true
done
else
echo " No node_modules directory here; run from project root."
fi
echo "=== [3/4] Checking GPU exporter exposure (port 9400 / DCGM) ==="
if ss -tlnp 2>/dev/null | grep -E ':9400'; then
echo "[CHECK] Port 9400 is listening. Verify bind address:"
ss -tlnp | grep ':9400'
if ss -tln | grep -E '0\.0\.0\.0:9400|\[::\]:9400'; then
echo "[ALERT] Exporter bound to all interfaces. Restrict to localhost or the monitoring subnet immediately."
fi
else
echo " Port 9400 not listening on this host."
fi
echo "=== [4/4] Firewall check for 9400 ==="
if command -v iptables >/dev/null 2>&1; then
iptables -L INPUT -n | grep 9400 || echo " No iptables rule references 9400 — add one (see Remediation section)."
fi
echo "=== Audit complete. Review all [ALERT] and [REVIEW] lines. ==="
Remediation
For the Tensorlake npm SDK compromise:
- Identify exposure immediately. Search all
package.json, lockfiles, and private registry caches fortensorlake. Determine whether the compromised version was installed anywhere — including CI build logs, which often record resolved versions. Treat any environment that installed the affected version as potentially compromised, not merely exposed. - Rotate credentials on any host that installed the package. This is the non-negotiable step teams skip. Rotate npm tokens, cloud IAM credentials (AWS/GCP/Azure), SSH deploy keys, and any secrets present in CI environment variables on affected runners. Assume exfiltration occurred.
- Pin and gate dependencies. Enforce lockfile-only installs (
npm ci, notnpm install) in CI. Deploy a private registry proxy (e.g., Artifactory/Nexus or a scoped allowlist) with a quarantine window — new package versions should not reach production builds for a defined soak period (24–72 hours blocks most fast-moving package compromises). - Disable lifecycle scripts where feasible.
npm config set ignore-scripts truefor CI builds, with explicit exceptions for packages requiring native builds. This single control would have blunted the execution vector entirely. - Hunt before you close. Run the Sigma, KQL, and VQL content above across your fleet. Look for the post-install behaviors, not just the package name — the poisoned version window may predate your awareness.
For exposed NVIDIA GPU monitors:
- Inventory your exporter footprint. External attack surface scan (or a Shodan/Censys query against your ASN and domains) for port 9400 and known exporter paths (
/metrics). Include cloud GPU instances, which are frequently spun up with permissive security groups by data science teams. - Bind exporters to localhost or the monitoring VLAN. DCGM exporter and node-exporter-style tools should never be reachable from the internet or from general user subnets. Scrape via Prometheus from an allowlisted source only.
- Enforce firewall policy. Example:
iptables -A INPUT -p tcp --dport 9400 -s <PROMETHEUS_SUBNET> -j ACCEPTfollowed byiptables -A INPUT -p tcp --dport 9400 -j DROP. In cloud environments, fix the security group — do not rely on host firewalls alone. - Add authentication where the exporter supports it, or front it with a reverse proxy enforcing mTLS or basic auth at minimum. Telemetry without auth is a reconnaissance feed.
- Treat leaked telemetry as targeting data. If your endpoints were exposed, assume driver/GPU version inventory and workload patterns are known to adversaries. Patch NVIDIA drivers and DCGM per current vendor guidance, and expect tailored follow-on activity against AI/ML infrastructure.
For the broader tradecraft trends (AI-assisted intrusion, content-based C2):
- Recalibrate phishing detection for higher-quality, well-localized lures — grammatical sloppiness is no longer a reliable signal. Weight behavioral signals (new domain, first-time sender, anomalous attachment behavior) over linguistic ones.
- For dead-drop C2, invest in beaconing detection (periodic low-volume connections to content platforms) and egress allowlisting on servers that have no business fetching social media or paste-site content.
Executive Takeaways
If you do three things this week: (1) sweep your dependency trees and CI logs for the Tensorlake SDK and rotate credentials anywhere it was installed, (2) confirm no GPU telemetry exporters are internet-reachable, and (3) deploy the package-manager child-process detection — it will catch the next npm compromise, not just this one. Supply chain intrusions through developer tooling are now a weekly event, and the organizations that survive them are the ones that treat CI/CD infrastructure as the high-value target it is.
Related Resources
Security Arsenal Incident Response Services AlertMonitor Platform Book a SOC Assessment incident-response Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.