Product
A malicious npm release of the TensorLake TypeScript SDK (v0.5.144) uses a preinstall hook to exfiltrate developer credentials and AI-tool configurations while maintaining remote command execution capabilities.