Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm
- Posted on October 8, 2026
- By The Hacker News
- 0 Views
- 1 min read
In brief
Generating AI summary…
Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm
Malicious tensorlake npm version 0.5.144 contained a Shai-Hulud worm that harvests credentials and can republish compromised packages.