{ads}

Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm



October 8, 2026 at 11:16AM

The npm package known as "tensorlake," a TypeScript software development kit (SDK) for Tensorlake applications, sandboxes, and cloud services, was compromised as part of a ChainDrop / Shai-Hulud supply chain attack. The malicious version 0.5.144 "contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code," Socket said

from The Hacker News https://ift.tt/4It12hG

0 Response to "Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm"

Post a Comment

Article Top Ads

Central Ads Article 1

Middle Ads Article 2

Article Bottom Ads