LIVE FEED
Tensorlake npm Package Hijacked by Shai-Hulud Worm

Tensorlake npm Package Hijacked by Shai-Hulud Worm

ATLAS OWASP CRITICAL Active exploitation · Immediate action required ▲ 8.5 The Hacker News

The tensorlake npm package (version 0.5.144) was compromised as part of a supply chain attack delivering the Shai-Hulud credential-stealing worm, which harvests tokens, SSH keys, AWS credentials, and configuration files from AI developer tools including Anthropic Claude, Cursor, and Windsurf. The self-propagating worm republishes compromised packages under victim maintainer identities and uses an Ethereum smart contract for C2 resolution, with a destructive 'hostage token' mechanism triggered if victims revoke stolen GitHub tokens. The attack specifically targets AI/ML developer toolchains, making it directly relevant to teams building on or integrating with Tensorlake-based infrastructure.

◉ AI THREAT BRIEFING

Stay ahead of the threat.

Twice-weekly digest of critical AI security developments — every story mapped to MITRE ATLAS and OWASP LLM Top 10. Free.

No spam. Unsubscribe anytime.