Security

Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm

The npm package tensorlake, a TypeScript SDK for Tensorlake applications and services, is compromised in a ChainDrop / Shai-Hulud supply-chain attack. Malicious version 0.5.144 harvests credentials, exfiltrates secrets, persists, and can execute remotely supplied code.

Image: The Hacker News

Why it matters

Developers using the affected package version face potential credential theft, secret exfiltration, and remote code execution. Identifying the compromised version helps affected teams assess their exposure.

Coverage 1 publisher

  1. The Hacker News

    Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm

Articles stay on their publishers’ sites; each link opens the original.