Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm

The npm package known as “tensorlake,” a TypeScript software development kit (SDK) for Tensorlake applications, sandboxes, and cloud services, was compromised as part of a ChainDrop / Shai-Hulud supply chain attack.

The malicious version 0.5.144 “contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code,” Socket said

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations,

Where are YC founders now? OpenAI and Anthropic, mostly

Where are YC founders now? OpenAI and Anthropic, mostly Source: Hacker News

New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data

New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data Adversa AI has disclosed an attack technique that it says can cause xAI’s Grok chatbot to send