A malicious Tensorlake release runs on installation, before a developer uses it.
Aikido says it seeks credentials and can spread to other projects.…

A malicious Tensorlake release runs on installation, before a developer uses it.
Aikido says it seeks credentials and can spread to other projects.…
Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm reconbee.com/tensorlake-n...
#tensorlake #npmpackage #npm #shaihulud #credential #cybersecurity #cyberattack
Tensorlake version 0.5.144 contained Shai-Hulud, designed to steal access credentials and spread through packages a user could publish.
The releas…