Analysis: Tensorlake npm SDK compromise, Nvidia GPU telemetry leaks and AI-driven Korean bank attacks
A breakdown of three Q4 2026 incidents: the Tensorlake npm SDK compromise, exposed Nvidia GPU monitoring dashboards and AI-augmented attacks on South Korean banks. The author links them into a single chain of supply-chain and operational security failures.
- Tensorlake SDK compromise replicated the MALFEX npm campaign pattern
- Exposed GPU dashboards reveal topology and compute schedules
- AI-generated phishing against Korean banks uses LinkedIn profile data
- All three vectors are mapped to MITRE ATT&CK techniques
Read next
Security