Skip to content

Tensorlake npm Package Compromised to Spread Shai

Cybersecuritynews •Tushar Subhra Dutta • October 8, 2026

A malicious release of the Tensorlake npm package has been published with a Shai-Hulud worm variant that can steal developer secrets and attempt to spread through connected software supply chains. The affected version, [email protected], was released on October 8, 2026. Tensorlake is a serverless sandbox platform for AI agents, and its npm package has recorded […]

Extracted Entities

Attack Types (1)

Malware (1)