Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm
The “tensorlake” npm package, a TypeScript SDK for Tensorlake applications, sandboxes, and cloud services, was compromised as part of a ChainDrop/Shai-Hulud supply chain attack. The malicious version 0.5.144 contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied commands, The Hacker News reports. Developers using the package should check for the tainted version and rotate any exposed secrets.