
Malicious Tensorlake SDK on npm stole crypto wallets and credentials
- —The infected 0.5.144 build was live on npm for 11 minutes; the package gets about 12,000 weekly downloads
- —The worm targeted crypto wallets, browser passwords, GitHub Actions secrets and cloud credentials
- —Its install script ran outside Tensorlake's sandbox and inherited the installing process's permissions
- —If a stolen GitHub token was revoked, the worm could wipe the user's home directory
Why it matters: Developers who installed the SDK on October 8 should audit systems and rotate any exposed keys and wallets.
Source: DiarioBitcoin