Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm
The Hacker News October 8, 2026

Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm

Malicious tensorlake npm version 0.5.144 contained a Shai-Hulud worm that harvests credentials and can republish compromised packages.

Advertisement

Advertisement

More like this