socket-dev · Crawled Oct 8, 2026
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
5 IoCs
Read original article ↗
AI Summary
The npm package [email protected] was compromised in a supply chain attack linked to the ChainDrop/Shai-Hulud campaign, delivering a credential-stealing malware payload via a preinstall hook. The malicious code executes during installation, harvesting secrets from local files, CI environments, Kubernetes, Vault, and AI development tools, then exfiltrates them. The payload also establishes persistence using a 'hostage token' mechanism that triggers destructive actions if stolen tokens are revoked, and it propagates by republishing compromised npm packages under the victim's identity.
AI-extracted · verify before operational use