Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm
Wednesday, 7 October 2026
Add Comment
The npm package known as "tensorlake," a TypeScript software development kit (SDK) for Tensorlake applications, sandboxes, and cloud services, was compromised as part of a ChainDrop / Shai-Hulud supply chain attack. The malicious version 0.5.144 "contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code," Socket said
from The Hacker News https://ift.tt/4It12hG
Genrerating Link.... 15 seconds.
Your Link is Ready.
0 Response to "Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm"
Post a Comment