Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm
Security

Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm

The Hacker News · Oct 08, 2026

Back to News
Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm
Security October 8, 2026

The npm package known as "tensorlake," a TypeScript software development kit (SDK) for Tensorlake applications, sandboxes, and cloud services, was compromised as part of a ChainDrop / Shai-Hulud supply chain attack. The malicious version 0.5.144 "contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code," Socket said

Read original on The Hacker News

Want to stay informed about new business solutions?

Follow us

Ready to build a better digital experience?

We create modern multilingual websites, integrate external services and automate content workflows for growing businesses.