Cloud Security, Application security, Third-party code

Tensorlake npm package compromised in supply chain attack

(Adobe Stock)

The npm package "tensorlake," a TypeScript software development kit for Tensorlake applications, was compromised as part of a ChainDrop / Shai-Hulud supply chain attack, based on information published by The Hacker News.

The malicious version 0.5.144 of the tensorlake package contained obfuscated malware designed to harvest credentials, exfiltrate secrets, establish persistence, and execute remotely supplied code. The malware targeted a wide range of sensitive information, including npm tokens, GitHub tokens, AWS credentials, Kubernetes credentials, SSH keys, cryptocurrency wallets, and configuration files for AI tools like Anthropic Claude. It also dropped the HackBrowserData binary and used an Ethereum contract for command-and-control, with GitHub as a fallback. The attack propagated by enumerating associated packages, building Sigstore provenance, and republishing compromised versions. This incident extends the supply chain attack to AI agent infrastructure, highlighting the increasing trend of threat actors targeting AI tools and services for data extraction. Users who installed the malicious version are advised to remove it immediately and rotate their credentials.

Source: The Hacker News

An In-Depth Guide to Cloud Security

Get essential knowledge and practical strategies to fortify your cloud security.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds