Compromised Tensorlake npm Package Exploited to Distribute Shai-Hulud Credential-Stealing Worm
A compromised npm package 'tensorlake' was used to distribute the Shai-Hulud credential-stealing worm, exploiting supply chain vulnerabilities to steal secrets across AI infrastructure. The malware employs obfuscation, persistence mechanisms, and Ethereum C2 communication to exfiltrate credentials and establish remote access.
The npm package known as "tensorlake," a TypeScript software development kit (SDK) for Tensorlake applications, sandboxes, and cloud services, was compromised as part of a ChainDrop / Shai-Hulud supply chain attack.
The malicious version 0.5.144 "contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code," Socket said
*** END OF TRANSMISSION ***