Tensorlake npm Package Compromised in ChainDrop/Shai-Hulud Supply Chain Attack
Malicious version 0.5.144 delivers credential-stealing worm to SDK users

Key Takeaways
- The tensorlake npm package version 0.5.144 was compromised in a supply chain attack.
- The malware harvests credentials, exfiltrates secrets, establishes persistence, and enables remote code execution.
- The attack is attributed to the ChainDrop/Shai-Hulud campaign.
- Developers using the tensorlake SDK are at risk of credential theft and data exfiltration.
Related Security News

Unpatched AhsayCBS Vulnerabilities Exploited in the Wild to Deploy Webshells and Cryptominers
Threat actors are exploiting two unpatched vulnerabilities in the AhsayCBS backup management platform. One vulnerability is rated critical severity and another medium severity. The exploitation has been observed in the wild and is being used to deploy webshells for persistent access and cryptocurrency miners for monetization. No patches are currently available, and the vulnerabilities remain unpatched. Affected organizations using AhsayCBS for backup management are at risk of persistent compromise and resource misuse.




