A worm was found in Tensorlake SDK version 0.5.144
Researchers say a user must disable the token monitor of the worm before the user revokes tokens.
On Thursday, researchers found the Shai-Hulud worm in version 0.5.144 of the Tensorlake SDK package on npm. About 12,000 copies of the package are downloaded each week. The worm steals credentials. The worm can erase the home directory of a user when the user revokes a GitHub token that the worm steals. Socket flagged the version 11 minutes after npm published it. npm and Tensorlake removed the version.
Sources
Posted