Tensorlake npm Package Compromised With Credential-Stealing Malware
A recent version of the TypeScript SDK npm package 'tensorlake' was compromised to include malware that steals credentials, establishes persistence, and enables remote code execution. The malicious update, version 0.5.144, harvested secrets from local files and cloud environments, and republished itself to spread further. It was released after attackers pushed malicious files using legitimate maintainer credentials. The infected package has been removed from npm's registry.
- Malicious update harvested credentials and secrets
- Targeted local, CI, Kubernetes, and Vault sources
- Spread via compromised publisher's package associations
- Used novel persistence and destructive tactics
- Malicious version removed from npm registry
Sources covering this
More in Cybersecurity
US and allies disrupt Chinese hacking tools targeting infrastructure
US authorities and international partners have seized domains and tools used by China's Integrity Technology Group to support…
AI-powered attacks target South Korean banks
A cyberattack campaign targeting South Korean financial institutions used AI-based tools to steal personal data, CrowdStrike reported.
Google promotes passkeys as a password alternative
Google is highlighting passkeys as a faster and safer alternative to traditional passwords for its accounts.
Malware found pre-installed on low-cost Android phones
Researchers have discovered malware embedded in the firmware of inexpensive Android smartphones, allowing attackers to remotely install…