chiprook
← Security
SecurityOctober 8, 2026, 12:46

Tensorlake npm package compromised to spread Shai-Hulud credential-stealing worm

Version 0.5.144 of the tensorlake npm package, a TypeScript SDK for Tensorlake services, was compromised in a ChainDrop / Shai-Hulud supply chain attack. The malicious code harvests credentials, exfiltrates secrets, establishes persistence and executes remotely supplied code.

Tensorlake npm package compromised to spread Shai-Hulud credential-stealing worm
#Tensorlake#Npm
Read next
Security

TanStack npm supply-chain attack: Mini Shai-Hulud worm hit 42 packages

Security

Mandiant: hijacked AI coding session spread Shai-Hulud worm across ~100 repos

Security

Shai-Hulud npm worm ran code just by opening a folder

Security

Compromised MemTensor packages push sckit credential stealer via npm and PyPI