Tensorlake NPM package and repo compromised

(github.com)

9 points | by varunsharma07 10 hours ago ago

1 comments

  • vgopiyamparala 10 hours ago ago

    StepSecurity team member here if you are running Tensorlake in your environments, please audit your build pipelines and lockfiles immediately. Check for unexpected lifecycle scripts or unauthorized package version bumps, and make sure to revoke any exposed publish or deployment tokens.