The Hacker News

Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm

The npm package known as "tensorlake," a TypeScript software development kit (SDK) for Tensorlake applications, sandboxes, and cloud services, was compromised as part of a ChainDrop / Shai-Hulud supply chain attack. The malicious version 0.5.144 "contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code," Socket said

By The Hacker News

1 min read
Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm
AI-generated illustration

Got news to share with the events industry?

Submit a press release or story tip and reach thousands of event professionals.

Get in touch→

More in Cybersecurity, Cryptography & Digital Trust

Related Insights