Tensorlake npm Package Compromised to Distribute Credential-Stealing Malware
The tensorlake npm package, a TypeScript SDK for Tensorlake applications and cloud services, was compromised in a supply chain attack dubbed ChainDrop or…
If your team uses tensorlake in projects, immediately verify which versions are installed and upgrade to a safe version (later than 0.5.144) as soon as available. Review access logs for secrets and credentials during the period the compromised version was active. Implement monitoring for suspicious traffic on systems that ran this package.