Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm

The npm package known as “tensorlake,” a TypeScript software development kit (SDK) for Tensorlake applications, sandboxes, and cloud services, was compromised as part of a ChainDrop / Shai-Hulud supply chain attack.

The malicious version 0.5.144 “contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code,” Socket said

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Linux 7.2

Linux 7.2 Source: Hacker News

CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners

CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known

ChatGPT Desktop (Codex Desktop) for Linux

ChatGPT Desktop (Codex Desktop) for Linux Source: Hacker News