Severity: HighAction: Be aware

In Other News: AI Used in Korean Bank Breaches, Poem-Guided Botnet, Empire Admin Gets 40 Years

Noteworthy stories that might have slipped under the radar: Tensorlake npm SDK compromised, Empire Market co-founder gets 40 years, exposed NVIDIA GPU monitors leak telemetry.

Excerpt from the primary source: SecurityWeek

Who is affected

Developers

Affected technology: npm registry

What you should do · Be aware

No immediate action is indicated. Share this with the relevant teams and watch for updates.

Automated guidance based on this story's classification. Check the linked advisories for specifics.

Sources

We link to original and authoritative sources. Headlines and excerpts belong to their publishers.

Original reporting

In Other News: AI Used in Korean Bank Breaches, Poem-Guided Botnet, Empire Admin Gets 40 Years SecurityWeek · securityweek.com · Oct 9, 2026 · Primary source
Severity: HighAction: Be aware

Malicious npm Packages That Evade Defenses

This is an impressive piece of malware . Its sophistication says nation-state to me, but there is no direct evidence and certainly no attribution.

Severity: HighAction: Be aware

Shai-Hulud Attack Nips Cyber-Firm CrowdSec's GitHub Data

Threat actors stole the contents of 170 private repositories using an OAuth token stolen from a former employee's computer through the TanStack npm supply chain attack.

In Other News: AI Used in Korean Bank Breaches, Poem-Guided Botnet, Empire Admin Gets 40 Years | CybersecurityNews.us