WORLDTECH NEWS Global technology intelligence.Contact
← Back to WORLDTECH
Cybersecurity DEVELOPING

Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm

Analyst seen from behind facing a wall of blurred monitoring screensAI illustration
WORLDTECH illustration · AI-generated (Canva)

What happened

The npm package known as "tensorlake," a TypeScript software development kit (SDK (the toolkit a developer builds on a platform with)) for Tensorlake applications, sandboxes, and cloud services, was compromised as part of a ChainDrop / Shai-Hulud supply chain attack (an attack that reaches a target through software it depends on).

Sources & evidence