source&pool
A daily wire of long-form journalism, video, and discourse — filed, tagged, and laid out flat.
VOL. I·NO. 01
FRIDAY, OCTOBER 9, 2026
  1. 001X 主题热门OCT · 08English

    malicious approval · X 热门 · 2026-10-08 20:03 UTC

    Tensorlake's TypeScript SDK was compromised for 102 minutes with the Shai-Hulud worm, a malware designed to steal GitHub and AWS credentials. The attacker used stolen employee credentials to inject malicious code. The package was removed immediately, and Tensorlake implemented multiple security measures including hardware security keys, signed commits, and two-person approval for package publishing.

  2. 002Hacker NewsOCT · 08English

    Tensorlake is compromised using mini Shai Hulud

    Tensorlake npm package was compromised with Mini Shai-Hulud, a credential-stealing worm affecting ~106,000 monthly downloads. The attacker used a compromised repository administrator account to inject malicious code through GitHub's web interface, which npm served as the latest version before removing it eight minutes after SafeDep's detection.

    By Kunal Singh