Compromised Tensorlake npm release carries Shai-Hulud credential theft malware
The affected release is version 0.5.144 of the Tensorlake npm package. Socket says its hidden malware collects credentials, sends secrets outside the system, maintains access and runs remotely supplied code, according to The Hacker News. The worm can also attempt to spread through connected software supply chains, Cyber Security News reports.
- Version 0.5.144 was released October 8, 2026, according to Cyber Security News.
- The package is a TypeScript SDK for Tensorlake services, according to The Hacker News.
Covered by 2 publishers within 10 hours of the first report.
Reporting2
The Hacker News Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm · info@thehackernews.com (The Hacker News)
Cyber Security News Tensorlake npm Package Compromised to Spread Shai-Hulud Worm and Steal Developer Secrets · Tushar Subhra Dutta