Supply Chain Attack Hits Tensorlake SDK, Injects Credential-Stealing Worm
A malicious version of the popular Tensorlake TypeScript SDK, distributed through the npm registry, has been identified as the latest vector in a sophisticated supply‑chain intrusion known as the ChainDrop or Shai‑Hulud campaign. The compromised package, version 0.5.144, was discovered to contain heavily obfuscated code that installs a credential‑stealing worm on developers' machines.
The Tensorlake SDK is widely used for building applications that interact with Tensorlake's sandboxed environments and cloud services. By hijacking the package at the source, attackers were able to reach a large number of developers who automatically fetch dependencies via npm, a standard practice in modern JavaScript and TypeScript projects. Once installed, the hidden payload activates, harvesting authentication tokens, API keys, and other sensitive data before exfiltrating it to remote servers controlled by the threat actors.
Security researchers who first reported the breach, citing The Hacker News, noted that the malicious code employs multiple layers of obfuscation to evade static analysis tools. The worm appears to be designed for persistence, embedding itself in the host environment and attempting to spread to other projects that share the same dependency tree. This mirrors previous supply‑chain attacks such as the infamous event‑stream incident, underscoring the growing risk of third‑party code being weaponized.
Tensorlake's maintainers responded quickly, revoking the tainted version from the npm registry and publishing a security advisory urging users to downgrade to a clean release or run integrity checks. The incident has reignited calls within the open‑source community for stronger verification mechanisms, such as reproducible builds, stricter publishing permissions, and automated scanning for malicious patterns before packages reach the public registry.
For developers, the episode serves as a reminder to adopt best practices: lock dependency versions, employ lockfiles, and integrate security tooling like npm audit or third‑party scanners into CI pipelines. Organizations are also advised to monitor for abnormal credential usage and to rotate any tokens that may have been exposed. As supply‑chain threats continue to evolve, the industry is likely to see increased investment in provenance tracking and collaborative defenses to protect the software supply chain from similar attacks in the future.
Comments (0)
Be the first to comment.
Join the discussion