The Intake — Thursday, October 8, 2026

On the substrate

Tensorlake npm package compromised by a self-propagating worm; payload explicitly targets AI tool configuration files

The Register Socket.dev The Hacker News

If you use Tensorlake's npm package in your AI infrastructure pipeline, version 0.5.144 is compromised. It was published October 8, 2026. A patched version, 0.5.145, is available now.

The payload is a self-propagating worm. It establishes a C2 channel. The worm then uses the victim's npm credentials to re-publish compromised versions of other packages. The exfiltration list names crypto wallets, browser passwords, GitHub Actions secrets, SSH keys, and cloud credentials. It also explicitly names configuration files for Claude, Cursor, Kiro, and Windsurf. A dead-man switch triggers home-directory deletion if a stolen GitHub token is subsequently revoked.

Socket detected the malicious version 11 minutes after it was published. The package has approximately 12,000 weekly downloads.

If your environment has Tensorlake alongside AI tool config files, both were in scope. Updating to 0.5.145 closes the infection path. Any credentials the compromised version may have touched are the immediate follow-on to audit.

PoeLLM malware routes 3,400 infected AI infrastructure servers through a C2 address encoded in a GitHub poem

Lumen Black Lotus Labs The Register Help Net Security

If you're running LiteLLM, Ollama, Gitea, or Gotenberg in your infrastructure, a campaign called "Canto Incognito" has been actively targeting those services. Lumen Black Lotus Labs published the research on October 7, 2026.

The malware, PoeLLM, stores its C2 server address inside a poem titled "On the Nature of Connection." The poem sits in a GitHub repository disguised as a Node.js fork. The repository hosts it in a file named dash.css. Four words from the poem map through a hardcoded dictionary to construct an IPv4 address. Updating the poem redirects all infected systems to a new C2 server.

LiteLLM is the named entry path via CVE-2026-42271, a command-injection vulnerability. The campaign has compromised more than 3,400 servers since April 2026. Peak daily infections exceeded 800. Targets are primarily in the US and Western Europe.

If you're running any of these four services and haven't reviewed CVE-2026-42271's applicability to your LiteLLM deployment, that's the named entry point.

Anthropic's 950-agent DNA scan identifies CRISPR-like enzyme candidates; priority dispute emerges on the same day

Anthropic CNN / KRDO Smithsonian Magazine

Anthropic deployed 950 Claude agents to analyze a bacteriophage DNA database. The run lasted 21 hours and consumed 210 million tokens. The agents identified 3,500 candidate enzyme sequences. Twenty exhibited structural similarity to CRISPR Cas-9, the gene-editing mechanism. Anthropic published the findings as a preprint on September 24, 2026. The preprint has not been peer reviewed.

Coverage on October 8 surfaced a priority dispute. University of Copenhagen PhD student Mario Rodríguez Mestre said his own unpublished research describes the same viral signatures. He named training data contamination as one possible explanation. Understated human direction in the experiment design was the other. MIT's Feng Zhang described the finding as "genuinely intriguing."

The methodology dispute is unresolved; the preprint hasn't been peer reviewed. No near-term practitioner implication from the finding itself.

---

For operators

Goodfire launches activation-probe monitoring at $51 per 1,500 sessions with 94% detection on malicious agent runs

TechCrunch Crypto Briefing SuperpowerDaily

If you've been relying on a model-reviewer to catch malicious agent sessions, Goodfire's October 8 cost comparison shows activation probes can do the same job at a fraction of the price.

Goodfire's probe classifiers run directly on a model's intermediate neural activations during inference — not its final output. The probes are available via a Baseten partnership. Goodfire tested them on Kimi K3. Running four probes simultaneously, Goodfire detected 94% of malicious hacking sessions in its testing. The reported false-positive rate on benign sessions was 8.7%. Goodfire says adding four probes increases response latency by less than 2%.

For approximately 1,500 agent sessions, Goodfire probes run at approximately $51. The comparison: a mid-tier LLM reviewer at approximately $233, a premium LLM reviewer at approximately $10,000.

If you're running a premium model reviewer at scale, the cost gap is a real line item. The 8.7% false-positive rate is the number to model against your own session volume. That modeling determines whether activation-probe monitoring works as your main detection layer.

GitHub Copilot CLI in autopilot mode was used to exfiltrate local secrets via a technique the vendor declined to classify as a vulnerability

Adversa AI The Register CyberPress

If your GitHub Copilot CLI is set to autopilot mode and you visit attacker-controlled URLs during a session, a full exfiltration chain has been documented. Adversa AI published the research on October 6, 2026. No patch has been released.

Adversa AI's technique — which they named CCI — delivers a ciphertext from an attacker-controlled web page. One decryption key requires reading a local file, for example .env.prod. The decryption attempt itself exfiltrates the file contents. A second key then unlocks instructions to transmit the data externally.

Adversa AI disclosed CCI to GitHub on September 17, 2026. GitHub declined to classify it as a vulnerability. Adversa AI tested Microsoft's mai-code-1.1-flash model. It executed the full attack chain in 50% of runs. A complete .env.prod file was exfiltrated in approximately 28 seconds. GPT-5.6 refused in 100% of runs.

If you're on automatic model selection, you have no visibility into which model processes your session. If you use Copilot CLI's autopilot mode with .env files in scope, the affected model is mai-code-1.1-flash. The exploitable surface is any attacker-controlled URL visited during a session.

---