Tensorlake npm Package Compromised to Spread Shai-Hulud Worm and Steal Developer Secrets

A malicious release of the Tensorlake npm package has been published with a Shai-Hulud worm variant that can steal developer secrets and attempt to spread through connected software supply chains. The affected version, tensorlake@0.5.144, was released on October 8, 2026. Tensorlake is a serverless sandbox platform for AI agents, and its npm package has recorded […]

This article has been indexed from Cyber Security News

Read the original article: