TGViewer
SITREP - Independent OSINT Channel SITREP - Independent OSINT Channel @sitreports · 23K subscribers
Post #39540 289
🔍 Shai-Hulud hits AI tooling via Tensorlake SDK

A malicious release of Tensorlake’s SDK version 0.5.144 on npm was flagged 11 minutes after publication and later removed. Researchers link the package to the credential-stealing Shai-Hulud worm, with code overlap to the ChainDrop variant. Reported theft targets include cloud credentials, GitHub Actions secrets, browser passwords, crypto wallets, and service-account tokens.

The case shows how AI-agent platforms remain exposed through the developer and CI/CD layer rather than the runtime sandbox itself. Installation scripts execute with host permissions, meaning a short-lived package compromise can still reach build runners, deployment secrets, and token stores before any isolation controls apply.

🛰️ Open sources - closed narratives
@sitreports
More from @sitreports
  1. Oct 9, 2026🔍 Nvidia patches high-severity DCGM Exporter flaw Researchers identified roughly 2,100 in…
  2. Oct 9, 2026🔍 FBI details China-linked email access portal The FBI says China-linked hackers operated…
  3. Oct 9, 2026📡 Ransomware disrupts Japan’s IDCF Cloud IDC Frontier says a ransomware attack hit its ID…
  4. Oct 9, 2026🔍 FakeGit reactivates at scale on GitHub FakeGit has resumed activity with 17,610 malicio…
  5. Oct 9, 2026🔍 Cisco flags five critical NX-OS flaws on Nexus switches Cisco has issued advisories for…
  6. Oct 9, 2026🔍 Low-cost Android phones found shipping with firmware-level malware Bitdefender’s Midnig…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →