Supply Chain Attack Through Tensorlake npm Package Steals Credentials and Spreads Malware
558/69 Friday, October 9, 2026 Cybersecurity researchers have disclosed that version 0.5.144 of the tensorlake package on npm was compromised with malware as part of a supply chain campaign linked to ChainDrop/Shai-Hulud. The malware executes during package installation through a preinstall script and is designed to steal credentials and sensitive information from developer systems, including […]
