Skip to main content

Tag: tensorlake

1 article

Brightly-lit coding workspace with laptop and development tools, subtle network infrastructure in background.

Malware Worm Exploits Tensorlake npm Package to Steal Credentials

A malware worm has been discovered exploiting the popular Tensorlake npm package to steal sensitive credentials, with the first malicious commit occurring on October 7, 2026, at 01:20 a.m. UTC. The compromised package, version 0.5.144, was quickly taken down after publishing to the npm registry on October 8, 2026.

Analyst 207