Tag: tensorlake
1 article

Malware Worm Exploits Tensorlake npm Package to Steal Credentials
A malware worm has been discovered exploiting the popular Tensorlake npm package to steal sensitive credentials, with the first malicious commit occurring on October 7, 2026, at 01:20 a.m. UTC. The compromised package, version 0.5.144, was quickly taken down after publishing to the npm registry on October 8, 2026.