Tensorlake's TypeScript SDK was compromised for 102 minutes with the Shai-Hulud worm, a malware designed to steal GitHub and AWS credentials. The attacker used stolen employee credentials to inject malicious code. The package was removed immediately, and Tensorlake implemented multiple security measures including hardware security keys, signed commits, and two-person approval for package publishing.
Tensorlake npm package was compromised with Mini Shai-Hulud, a credential-stealing worm affecting ~106,000 monthly downloads. The attacker used a compromised repository administrator account to inject malicious code through GitHub's web interface, which npm served as the latest version before removing it eight minutes after SafeDep's detection.