Credential stealing malware detected within minutes of npm release, but impact remains unknown The credential hijacking Shai Hulud worm has struck again, this time burrowing its way into a popular AI agent platform SDK. Multiple security researchers reported Thursday that they had detected Shai Hulud infection in a recent release of the npm package for version 0.5.144 of Tensorlakes SDK. That package has somewhere in the neighborhood of 12,000 downloads per week, while its GitHub repository...

Read the full article at The Register