BREACH WATCH BRIEF High 🔗 Breach

Compromised “tensorlake” npm Package Delivers Credential‑Stealing Worm via Supply‑Chain Attack

The npm package tensorlake version 0.5.144 was published with malicious code that harvests credentials and runs remote code. The incident underscores the importance of continuous third‑party risk monitoring and audit‑ready evidence for supply‑chain security.

SeverityHigh
Type🔗 Breach
ConfidenceHigh
ReportedOct 8, 2026
Technology & SaaS Software development teams using npm packages Cloud service providers integrating the Tensorlake SDK Third-Party Dependency
Check if you use it. This incident came through a third party or the supply chain. If the product or supplier is in your estate or your vendors', start with the questions to ask below.

What happened

The npm package “tensorlake” (version 0.5.144) was compromised and now contains obfuscated malware that steals credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code.

Why it matters for trust and compliance

  • This supply‑chain breach illustrates why a continuous control‑assurance program must include vendor‑oversight, SBOM maintenance, and automated integrity checks to provide defensible audit evidence.
  • Demonstrates the need for continuous monitoring of third‑party components as part of a vendor risk program.
  • Provides evidence to support audit readiness for supply‑chain security controls.

Who is affected

Software development teams using npm packages Cloud service providers integrating the Tensorlake SDK

Recommended actions

  1. Generate an SBOM and verify package signatures against trusted sources.
  2. Remove the compromised version 0.5.144 and replace it with a clean release.
  3. Implement automated monitoring of npm registry changes for unexpected updates.
  4. Conduct a focused vendor risk assessment of the Tensorlake SDK provider.

Get the Breach Digest

The incidents that matter for your vendors and your data, analysed for practitioners, in one email.