A malicious version of the Tensorlake SDK, downloaded around 12,000 times per week, was briefly infected with the Shai-Hulud worm, which could have allowed attackers to hijack credentials and sensitive data. Fortunately, the issue was quickly detected and resolved, with the package being pulled and updated to a safe version.
Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm