October 8, 2026Technology·Bearish·cybersecurity
Shai-Hulud malware found in Tensorlake's AI agent SDK, pulled from npm
Malware dubbed Shai-Hulud was found in Tensorlake's AI agent SDK, with version 0.5.144 on npm able to search for cloud, GitHub and crypto wallet credentials. It was detected within minutes and removed, with Tensorlake publishing version 0.5.145; no data theft has been confirmed.
Detected & updated continuously · Source: Nebula
Story subjects
TensorlakeShai-Hulud