Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm
Summary
The npm package 'tensorlake' was compromised, distributing a malicious version 0.5.144. This version contains obfuscated malware designed to steal credentials, exfiltrate secrets, establish persistence, and execute remote code. The attack is part of a broader ChainDrop / Shai-Hulud supply chain campaign.
IFF Assessment
The compromise of a legitimate npm package to distribute credential-stealing malware is a significant threat to developers and organizations relying on these software components.
Defender Context
This incident highlights the persistent risk of supply chain attacks targeting popular software repositories like npm. Defenders should remain vigilant about package integrity, implement robust dependency scanning, and adopt a 'least privilege' approach to sensitive credentials and secrets management within development pipelines.