Tensorlake npm Package Compromised to Spread Shai-Hulud Worm and Steal Developer Secrets
A malicious release of the Tensorlake npm package has been published with a Shai-Hulud worm variant that can steal developer secrets and attempt to spread through connected software supply chains. The affected version, [email protected], was released on October 8, 2026. Tensorlake is a serverless...