Aikido reports that Tensorlake version 0.5.144, published on October 8, is malicious.
It runs during installation, before the package is used, and tries to steal access credentials and spread to other projects.
Aikido links it to a new Shai-Hulud variant.
The package has more than 100,000 installs overall, but that is not the install count for this specific version.
Aikido says its analysis found no signs of compromise…