Tensorlake npm SDK hijacked to spread Shai-Hulud worm with token-revocation wiper
Version 0.5.144 of the tensorlake npm package shipped a credential-stealing worm that can wipe a developer's home directory if the stolen GitHub token is revoked.
Cybersecurity news about “npm”.
Version 0.5.144 of the tensorlake npm package shipped a credential-stealing worm that can wipe a developer's home directory if the stolen GitHub token is revoked.
Checkmarx says a single actor has used npm packages since August 2023 to deliver Overlord RAT and a Node.js stealer; three packages were still live on October 1.