Shai-Hulud Just Infected an AI Agent Platform's npm Package — What Self-Hosted n8n Builders Must Do Now
On October 8, 2026, the npm package tensorlake — the TypeScript SDK for Tensorlake's AI agent infrastructure — was compromised by a new Shai-Hulud worm variant. Version 0.5.144 shipped a preinstall hook that stole npm tokens, GitHub tokens, AWS keys, SSH keys, .env files, crypto wallets, and browser passwords from every machine that installed it. The version was pulled within minutes, but the…
We haven't written up this one. Dev.to has the full story — the link below goes straight to it.