PulseAugur
EN
LIVE 21:28:15

Malware infects Tensorlake npm package, stealing credentials and targeting AI tools

The npm package `[email protected]` was compromised by a Shai-Hulud worm variant. This malware targets developer environments and CI/CD pipelines, with the capability to steal cloud and code repository credentials. It can also alter AI coding tool configurations and propagate to other npm packages. A particularly concerning feature is a "wipe switch" for GitHub tokens, which can lead to data destruction if not handled carefully. AI

IMPACT Compromised AI coding tools could lead to stolen credentials and potential sabotage of AI development pipelines.

RANK_REASON A specific software package was compromised, impacting its users and potentially their AI development tools.

Read on Mastodon — mastodon.social →

AI-generated summary · Google Gemini · from 1 sources. How we write summaries →

Malware infects Tensorlake npm package, stealing credentials and targeting AI tools

How we ranked this

Signal score
3 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
A specific software package was compromised, impacting its users and potentially their AI development tools.
Source corroboration
Single-source cluster
Only one publisher covered this so far. Single-source stories can still rank when the publisher is high-authority, but they lack cross-source corroboration.
Topics
product, safety
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
Breaking (< 6h)
Fresh story with cross-source coverage still developing. Ranking may shift as more sources report.

Full methodology in our editorial standards.

COVERAGE [1]

  1. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    🚨 Tensorlake npm Package Compromised by Shai-Hulud Worm The `[email protected]` npm release was compromised with a Shai-Hulud worm variant targeting developer

    🚨 Tensorlake npm Package Compromised by Shai-Hulud Worm The `[email protected]` npm release was compromised with a Shai-Hulud worm variant targeting developer environments and CI/CD pipelines. The malware can steal AWS, Azure, GCP, GitHub and npm credentials, modify AI coding to…