The Hacker NewsFriday · October 9, 2026FREE

Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm

securitynpmsupply-chainmalware

The Hacker News reported on October 8, 2026 that the Tensorlake npm package was compromised in order to deliver a credential-stealing worm identified as Shai-Hulud. According to the source, the compromise centers on the npm package itself, which served as the distribution channel for the worm. The malware is described as credential-stealing, and the incident is framed as a supply chain compromise affecting the package. The available source text does not specify which versions of the Tensorlake npm package were affected, when the malicious publication occurred, how many downloads or installations were involved, or what credentials the worm targets. It also does not describe the worm's propagation mechanism, persistence technique, or command-and-control infrastructure. No remediation guidance, package removal status, or maintainer response is included in the excerpt. The only concrete identifiers present are the package name, Tensorlake, the npm ecosystem, and the malware name Shai-Hulud.

// why it matters

Developers who installed the Tensorlake npm package may have exposed credentials to the Shai-Hulud worm, according to the source.

Sources

Primary · The Hacker News
▸ Read original at thehackernews.com

Like this? Get the next digest.