Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm

Summary

The npm package 'tensorlake' was compromised, distributing a malicious version 0.5.144. This version contains obfuscated malware designed to steal credentials, exfiltrate secrets, establish persistence, and execute remote code. The attack is part of a broader ChainDrop / Shai-Hulud supply chain campaign.

IFF Assessment

FOE

The compromise of a legitimate npm package to distribute credential-stealing malware is a significant threat to developers and organizations relying on these software components.

Defender Context

This incident highlights the persistent risk of supply chain attacks targeting popular software repositories like npm. Defenders should remain vigilant about package integrity, implement robust dependency scanning, and adopt a 'least privilege' approach to sensitive credentials and secrets management within development pipelines.

Read Full Story →