Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm
Overview
The npm package 'tensorlake' has been compromised in a supply chain attack, specifically linked to a malware variant known as Shai-Hulud. The affected version, 0.5.144, contains hidden malware designed to steal user credentials, exfiltrate sensitive information, maintain persistence on infected systems, and execute commands remotely. This incident poses a significant risk to developers and organizations using this SDK for their applications and cloud services, as it could lead to unauthorized access to critical systems and data. Users of the tensorlake package should immediately review their installations and consider updating or removing the compromised version to protect against potential breaches.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: npm package tensorlake version 0.5.144
- Action Required: Users should immediately remove version 0.
- Timeline: Newly disclosed
Original Article Summary
The npm package known as "tensorlake," a TypeScript software development kit (SDK) for Tensorlake applications, sandboxes, and cloud services, was compromised as part of a ChainDrop / Shai-Hulud supply chain attack. The malicious version 0.5.144 "contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code," Socket said
Impact
npm package tensorlake version 0.5.144
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Users should immediately remove version 0.5.144 of the tensorlake package and upgrade to a secure version if available.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Malware, Critical.