Cybersecurity DEVELOPING
Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm
First reported Source: The Hacker NewsLast editorial activity
What happened
The npm package known as "tensorlake," a TypeScript software development kit (SDK (the toolkit a developer builds on a platform with)) for Tensorlake applications, sandboxes, and cloud services, was compromised as part of a ChainDrop / Shai-Hulud supply chain attack (an attack that reaches a target through software it depends on).
Sources & evidence
- The Hacker News Reporting source
Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm ↗
https://thehackernews.com/2026/10/tensorlake-npm-package-compromised-to.html