A threat actor published a malicious version of the tensorlake npm package on October 8, 2026, embedding a new variant of the self-replicating Shai-Hulud supply-chain worm. The compromised release, tensorlake version 0.5.144, can steal developer secrets, target browser-stored cryptocurrency credentials, and use stolen publishing credentials to spread through connected software supply chains. The incident highlights […]
Read the original article:
