ConciseSignal
Following

Tensorlake npm Package Compromised With Credential-Stealing Malware

A recent version of the TypeScript SDK npm package 'tensorlake' was compromised to include malware that steals credentials, establishes persistence, and enables remote code execution. The malicious update, version 0.5.144, harvested secrets from local files and cloud environments, and republished itself to spread further. It was released after attackers pushed malicious files using legitimate maintainer credentials. The infected package has been removed from npm's registry.

Why it mattersDependency supply chain attacks like this can expose sensitive data and affect numerous projects that rely on compromised packages. The incident highlights ongoing risks for developers using third-party libraries.

Sources covering this

The Hacker NewsTensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm5:46 AM →The RegisterHeadline onlyShai-Hulud worm makes jump to AI infrastructure with Tensorlake compromise4:54 PM →
Concise Signal DailyEnterprise AI, security & business tech.Weekdays, 7am Eastern · Sample issue

More in Cybersecurity