Tensorlake npm Package Compromised to Deliver Shai-Hulud… | HappeningNow.news

Cybersecurity · 2 views

Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm

The npm package known as "tensorlake," a TypeScript software development kit (SDK) for Tensorlake applications, sandboxes, and cloud services, was compromised as part of a ChainDrop / Shai-Hulud supply chain attack.

Source Summary Published 2h 13m ago Brief Under 1 min brief
Story intelligence
Coverage Single outlet Single-outlet story
Views 2 Community interest
Brief read Under 1 min brief 17 words

Summary

Malicious tensorlake npm version 0.5.144 contained a Shai-Hulud worm that harvests credentials and can republish compromised packages.

Read original at The Hacker News

More from Cybersecurity

Continue reading recent Cybersecurity coverage

Support HappeningNow

Independent AI-powered news analysis is reader-supported. Your contribution helps cover infrastructure, summaries, and continued platform development.

Support HappeningNow

Report an issue with this page