Tensorlake npm Package Compromised to Spread Shai
A malicious release of the Tensorlake npm package has been published with a Shai-Hulud worm variant that can steal developer secrets and attempt to spread through connected software supply chains. The affected version, [email protected], was released on October 8, 2026. Tensorlake is a serverless sandbox platform for AI agents, and its npm package has recorded […]
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
