CyberSecurity News
Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm
AI summary
The tensorlake npm package was compromised in a supply chain attack, with the malicious version containing obfuscated malware. This malware is capable of harvesting credentials, exfiltrating secrets, establishing persistence, and executing remotely supplied code. The compromise is part of a larger ChainDrop and Shai-Hulud attack. The tensorlake package is a TypeScript SDK used for developing applications, sandboxes, and cloud services related to Tensorlake. The malicious version of the package is specifically identified as version 0.5.144.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

