Back to all news
Security

Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm

The Hacker News·October 8, 2026·1 min read
Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm

The npm package "tensorlake" was compromised in a ChainDrop/Shai-Hulud supply chain attack. Malicious version 0.5.144 contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code, according to security firm Socket. Developers using the TypeScript SDK should audit and rotate exposed credentials immediately.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store