Tensorlake npm package compromised to spread Shai-Hulud credential-stealing worm
Version 0.5.144 of the tensorlake npm package, a TypeScript SDK for Tensorlake services, was compromised in a ChainDrop / Shai-Hulud supply chain attack. The malicious code harvests credentials, exfiltrates secrets, establishes persistence and executes remotely supplied code.
- Compromised version is 0.5.144 of the tensorlake npm package
- Attack tied to the ChainDrop / Shai-Hulud supply chain campaign
- Malware harvests credentials and exfiltrates secrets
- Code establishes persistence and runs remote commands
Read next
Security