Malicious Tensorlake npm Package Steals Credentials
Original source
Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm
The Hacker News →The Tensorlake npm package was compromised in a supply chain attack, delivering a credential-stealing worm known as Shai-Hulud. The malicious version 0.5.144 contained obfuscated malware that harvested credentials, exfiltrated secrets, and executed remotely supplied code. The malware targeted various data types, including npm tokens, GitHub tokens, AWS credentials, and more. It also established persistence and propagated by republishing compromised versions of associated packages. The attack highlights the increasing targeting of AI tools and services by threat actors.
Read the full article
Continue reading at The Hacker News →This is an AI-generated summary. Read the original for the full story.