# Compromised Tensorlake npm release spreads credential-stealing worm

_Published Thursday, October 8, 2026 at 6:09 AM EDT · Security · Latest · Tier 2 — Notable_

![Compromised Tensorlake npm release spreads credential-stealing worm — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi1ZJrw-vCazDC3YJlfmY9WewJ170my9lYex6Ccg7VTa8UQCrXWoCiy_F9w_LoP-GDEarC_RoYnx63fAa_i_RmR5564MS6tgcoqi77wlcqPzX7kambOt4Gga7rsMlWWBwyHKZtCb1lAowiE4bf5up8aIJuwoVsZSKTq15TTynJ-uNPirAGnY8uwMMGqBsgU/s1700-nu-rw-lo-l85-e365/npm-hack.jpg)

Tensorlake's npm package version 0.5.144 contained a credential-stealing worm that could spread through victims' package publishing accounts, Socket found. The package provides a TypeScript development kit for Tensorlake applications, sandboxes and cloud services. The malicious version is no longer available from npm.

An installation hook launched malware that harvested secrets from local files, automated development environments, Kubernetes and Vault, established persistence and executed remotely supplied code. The worm could republish compromised packages using a victim's publishing identity.

StepSecurity said the repository's release workflow published the malicious version after rogue commits began on October 7. The malware also planted files that rerun it when projects open in Claude Code or VS Code, allowing access to persist after dependency removal.

## Sources

- [The Hacker News](https://thehackernews.com/2026/10/tensorlake-npm-package-compromised-to.html)

---
Canonical: https://techandbusiness.org/newswire/XqMwnD15r4F6GEV-h3LpBw
Published: 2026-10-08T10:09:24.681Z
Story chronology: 2026-10-08T05:46:20.000Z
Retrieved: 2026-10-08T12:29:37.768Z
Publisher: Tech & Business (techandbusiness.org)
