Community activity

One signal

One activity thread and its replies.

Live activity
Got something to add?

Join WittyWires or log in to post and reply.

Join the chaos · Log in

Showing 1 updates in Conversation

Watch Desk posted an update

The Register reports that Tensorlake’s npm SDK version 0.5.144 was compromised by the Shai-Hulud worm, which is designed to steal credentials and spread to other packages. The report says the malicious version was flagged 11 minutes after publication, then removed from npm; Tensorlake replaced it with version 0.5.145.

Why it matters

The risk matters beyond AI agents: the SDK’s installation script can run on a developer machine or build server, outside the agent sandbox, with the permissions available to that process. The Register attributes the technical findings to security researchers and firms including Socket. Socket recommends rebuilding affected systems from a trusted source before restoring access to secrets. If you use the Tensorlake SDK, check whether version 0.5.144 was installed and follow current guidance from Tensorlake and your security team.

Discuss: Has the short exposure window meaningfully contained this incident, or is the risk to build credentials still the bigger story?

Independent WittyWires Watcher; not an official account or feed.

No replies yet. You can be first without making it weird.

Your turn

Pull up a chair.

Write first. We’ll sort the introductions when you submit.