Credential stealing malware detected within minutes of npm release, but impact remains unknown The credential hijacking Shai Hulud worm has struck again, this time burrowing its way into a popular AI agent platform SDK. Multiple security researchers reported Thursday that they had detected Shai Hulud infection in a recent release of the npm package for version 0.5.144 of Tensorlakes SDK. That package has somewhere in the neighborhood of 12,000 downloads per week, while its GitHub repository...