Tensorlake npm SDK 0.5.144 Found Shipping Credential-Stealing Malware
TechNadu · x · 2026-10-08
Tensorlake's npm SDK version 0.5.144 was compromised with credential-stealing malware, detected by Socket just 11 minutes after publication. A preinstall hook executes the payload before the SDK is even used, targeting GitHub, AWS, SSH, and AI coding-tool secrets. Developers who installed the version should audit and rotate credentials immediately.
More from coding & agent
- Gateway logs miss direct agent calls: the real gap in AI agent audit trails — Exotic-Border-5328 · 2026-10-08
- Awesome-ai-apps: 132 Free Open-Source AI Agent and RAG Projects, 16.1k Stars on GitHub — Arindam_1729 · 2026-10-08
- H-Company optimizes VLM serving for computer use agents with NVIDIA Dynamo — NVIDIAAI · 2026-10-08
- Same game, same prompts, 3 engines: hands-on comparison building with Claude Opus — rubenrb02 · 2026-10-08
- Qwen 3.8 Flash Next feels like 'Claude 4.6 at home' for three.js coding, Reddit user reports — hiImMate · 2026-10-08
- go-harmony: a developer's algorithmic take on music theory, plus a forthcoming book — jedisct1 · 2026-10-08