
Data Breaches
Tensorlake NPM SDK Compromised in Supply Chain Attack
The Tensorlake npm SDK was found to contain malicious code, raising serious concerns about supply chain security for developers using the package.
Everything Payload Report has reported about npm: 2 stories, newest first. Part of our Data Breaches coverage.

The Tensorlake npm SDK was found to contain malicious code, raising serious concerns about supply chain security for developers using the package.

A critical remote code execution vulnerability in Handlebars allows attackers to inject arbitrary JavaScript via manipulated AST objects, prompting an urgent update.