Tensorlake npm SDK hijacked to spread Shai-Hulud worm with token-revocation wiper
Version 0.5.144 of the tensorlake npm package shipped a credential-stealing worm that can wipe a developer's home directory if the stolen GitHub token is revoked.
Cybersecurity news about “ChainDrop”.
Version 0.5.144 of the tensorlake npm package shipped a credential-stealing worm that can wipe a developer's home directory if the stolen GitHub token is revoked.