Tensorlake NPM package and repo compromised

9 pointsposted 10 hours ago
by varunsharma07

1 Comments

vgopiyamparala

10 hours ago

StepSecurity team member here if you are running Tensorlake in your environments, please audit your build pipelines and lockfiles immediately. Check for unexpected lifecycle scripts or unauthorized package version bumps, and make sure to revoke any exposed publish or deployment tokens.