Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm
The npm package tensorlake, a TypeScript SDK for Tensorlake applications and services, is compromised in a ChainDrop / Shai-Hulud supply-chain attack. Malicious version 0.5.144 harvests credentials, exfiltrates secrets, persists, and can execute remotely supplied code.
Developers using the affected package version face potential credential theft, secret exfiltration, and remote code execution. Identifying the compromised version helps affected teams assess their exposure.