Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm

The Hacker News - Oct 8, 2026

The npm package known as "tensorlake," a TypeScript software development kit (SDK) for Tensorlake applications, sandboxes, and cloud services, was compromised as part of a ChainDrop / Shai-Hulud supply chain attack. The malicious version 0.5.144 "contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code," Socket said

Read full article

More News

About Us
Logo

In-Depth Science delivers comprehensive and compelling news and analysis on everything science and technology, seven days a week in a reader-friendly format.

Contact us: sales[at]indepthscience.com

Copyright © 2015 - 2026 In-Depth Science. All Rights Reserved.