Compromised “tensorlake” npm Package Delivers Credential‑Stealing Worm via Supply‑Chain Attack
The npm package tensorlake version 0.5.144 was published with malicious code that harvests credentials and runs remote code. The incident underscores the importance of continuous third‑party risk monitoring and audit‑ready evidence for supply‑chain security.
SeverityHigh
Type🔗 Breach
ConfidenceHigh
ReportedOct 8, 2026
Technology & SaaS Software development teams using npm packages Cloud service providers integrating the Tensorlake SDK Third-Party Dependency
Check if you use it. This incident came through a third party or the supply chain. If the product or supplier is in your estate or your vendors', start with the questions to ask below.