npm package tensorlake@0.5.144 contains malicious preinstall payload

· GitHub ·

1 min read Original article ↗

Activity

  1. changed the title

    [-]npm package tensorlake@0.5.144 contains potentially malicious preinstall payload (possible worm)[/-] [+]npm package tensorlake@0.5.144 contains potentially malicious preinstall payload[/+]

    on Oct 8, 2026
  2. oliversmith-aikido commented on Oct 8, 2026

    @oliversmith-aikido

    Introduced here 41b38f0

    It's a new Shai-Hulud worm payload - information stealer, further details here

  3. changed the title

    [-]npm package tensorlake@0.5.144 contains potentially malicious preinstall payload[/-] [+]npm package tensorlake@0.5.144 contains malicious preinstall payload[/+]

    on Oct 8, 2026
  4. calavera commented on Oct 9, 2026

    @calavera

    We published a security advisory notice yesterday: GHSA-8g63-53c9-65j2

    Thanks for opening this issue.