Lotu Radar About

Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm

The Hacker News Cybersecurity Score 7/10
Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm

Summary

The npm package known as "tensorlake," a TypeScript software development kit (SDK) for Tensorlake applications, sandboxes, and cloud services, was compromised as part of a ChainDrop / Shai-Hulud supply chain attack. The malicious version 0.5.144 "contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code," Socket said

SecurityThreat Intel

Lotu Radar provides attributed news summaries and links to the original publisher. Full reporting and copyright remain with the source.