Tensorlake npm package was compromised with Mini Shai-Hulud, a credential-stealing worm affecting ~106,000 monthly downloads. The attacker used a compromised repository administrator account to inject malicious code through GitHub's web interface, which npm served as the latest version before removing it eight minutes after SafeDep's detection.