Shai-Hulud Worm Makes Jump to AI Infrastructure with Tensorlake Compromise
5 Articles
5 Articles
Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware
A threat actor published a malicious version of the tensorlake npm package on October 8, 2026, embedding a new variant of the self-replicating Shai-Hulud supply-chain worm. The compromised release, tensorlake version 0.5.144, can steal developer secrets, target browser-stored cryptocurrency credentials, and use stolen publishing credentials to spread through connected software supply chains. The incident highlights
A version of Tensorlake SDK distributed in npm contained the Shai-Hulud worm, designed to steal credentials and spread. Although the malicious package was detected 11 minutes after its publication and then removed, researchers warn that their installation could compromise equipment with access to development and deployment secrets.
Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm
The npm package known as "tensorlake," a TypeScript software development kit (SDK) for Tensorlake applications, sandboxes, and cloud services, was compromised as part of a ChainDrop / Shai-Hulud supply chain attack. The malicious version 0.5.144 "contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code," Socket said
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium








