# malicious approval — X 热门讨论 (2026-10-08 20:03 UTC)
## @diptanu (Diptanu Choudhury) · 10-08 17:17 · ♥20 ↻2 💬0 Tensorlake's Typescript SDK was compromised yesterday with Shai-Hulud worm for roughly 102 minutes. The package was removed the moment we found out about the incident.
We don't believe any users were affected as we track the SDK versions when users manage lifecycle of sandboxes. We can't decisively say who installed the package in their CI/CD pipelines. We have notified our users of this incident.
The attacker stole the credentials of an employee who is a GitHub admin of the SDK repository and committed the malicious code from a browser.
We have removed repository admin rights from all employees, reduced the organization to two owners protected by hardware security keys, blocked direct pushes to main for every account including owners, required signed commits, and placed every package publish behind a second-person approval.
Github Advisory - https://t.co/vz3FZFUz78 > 引用 @TheHackersNews: 🛑 Removing the npm package may not remove the malware.
Compromised tensorlake v0.5.144 shipped a Shai-Hulud worm designed to steal GitHub/AWS credentials, persist on hosts, and republish infected packages.
It's off npm. Installed it? Remove it and rotate credentials.
Read - https://t.co/EmlxyJBg5u https://x.com/diptanu/status/2108245527423013148