Tensorlake npm SDK 0.5.144 Found Shipping Credential-Stealing Malware

TechNadu · x · 2026-10-08

Tensorlake's npm SDK version 0.5.144 was compromised with credential-stealing malware, detected by Socket just 11 minutes after publication. A preinstall hook executes the payload before the SDK is even used, targeting GitHub, AWS, SSH, and AI coding-tool secrets. Developers who installed the version should audit and rotate credentials immediately.

Original post →

More from coding & agent

coding & agent channel →