In Other News: AI Used in Korean Bank Breaches, Poem-Guided Botnet, Empire
Version 0.5.144 of tensorlake — the npm SDK for Tensorlake's AI agent sandboxes — was compromised to run a credential-stealing worm at install time.
By Dillip Chowdary • Oct 10, 2026 • Source: SecurityWeek
Black Lotus Labs, GitGuardian, CrowdStrike, and U.S. federal prosecutors all published significant findings this week, together painting a picture of supply-chain attacks intensifying, dark-web marketplaces facing long-overdue justice, and AI tools appearing inside nation-state attack infrastructure. SecurityWeek's report aggregates nine stories that individually might have slipped past a busy security team but collectively reveal how quickly the threat landscape is shifting.
This article covers every story in that roundup in full — from a poem-powered botnet and a compromised npm package to a 40-year prison sentence and a high-severity Nvidia GPU monitoring flaw — with enough detail that practitioners, developers, and security-conscious readers can assess exposure without consulting the original source.
In Other News: what actually changed
Black Lotus Labs disclosed PoeLLM, a malware strain active since at least April 2026 that targets exposed AI and open-source services including LiteLLM, Ollama, Gotenberg, and Gitea. Infected machines pull four keywords from a poem hosted on GitHub, convert them into an IP address, and use that address to locate the current command-and-control server — a technique that lets the operator rotate infrastructure simply by editing words in a poem, which has been updated 11 times. The operator is assessed to be Italian-speaking. PoeLLM's purpose is cryptocurrency mining and botnet expansion.
GitGuardian, meanwhile, tracked the GhostAction supply chain campaign through August and September 2026, finding that its secret-stealing GitHub Actions workflow spread to 772 public repositories belonging to 373 users and organizations. The attacker targeted 2,577 secrets including SSH keys and credentials for Azure, AWS, and databases. Beyond a new exfiltration server, the campaign reused the same 2025 playbook almost unchanged, and GitGuardian's data indicates the operation never fully stopped between the two periods.
In Other News: how it works

The Tensorlake incident illustrates how supply chain attackers are embedding malware directly into package installation routines. Version 0.5.144 of tensorlake — the npm SDK for Tensorlake's AI agent sandboxes — was compromised to run a credential-stealing worm at install time. Researchers at Socket and Sonatype describe it as a ChainDrop/Shai-Hulud-style attack. The malware harvests npm, GitHub, AWS, Kubernetes, and Vault credentials alongside AI coding tool configurations, can execute attacker-supplied code remotely, and can republish itself through other packages the victim is authorized to publish, allowing lateral spread through the npm ecosystem.
CVE-2026-47483 affects Nvidia's DCGM Exporter GPU monitoring tool. Unauthenticated attackers can flood its profiling endpoints with requests to exhaust resources and crash the service, potentially disrupting AI workloads on the same host. Researchers scanning between March and May 2026 found roughly 2,100 hosts exposing the exporter to the internet without authentication, leaking telemetry from more than 12,000 GPUs. Nvidia has patched the flaw; the fix is in version 4.8.2 or later.
Advertisement
Tech Pulse Daily
Get tomorrow's pulse first
Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.
In Other News: why it matters now
South Korean President Lee Jae Myung stated publicly that there are signs AI was used in recent cyberattacks targeting the country's banks, leading to breaches of customer personal information. Police have opened a full-scale investigation. CrowdStrike reported finding Claude Code session histories, ARTEX configuration files, and Claude memory files while analyzing the attack infrastructure, and assesses with moderate confidence that a Chinese-speaking, financially motivated threat actor is likely responsible. The fact that an AI coding agent's artifacts appear inside confirmed bank-breach infrastructure marks a concrete, documented instance of AI tooling inside nation-state or nation-state-adjacent financial attacks.
CISA is simultaneously restructuring its own workforce incentives. The agency's Cybersecurity Retention Incentive program — worth up to 25 percent of base salary — will continue through fiscal 2027, but under tighter criteria: staff must hold an "exceeds expectations" rating or higher and spend at least 51 percent of their time on cyber duties within one of three designated job series. Employees outside those series who spend 75 percent or more on cyber work can apply for review board consideration. The overhaul followed a Department of Homeland Security inspector general finding that the program had been mismanaged and applied too broadly.
In Other News: who is affected
Jonathan Spalletta, 36, of Maryland, was convicted by jury on computer fraud and money laundering charges for two 2021 hacks of decentralized crypto exchange Uranium Finance. He exploited smart contract vulnerabilities to steal approximately $1.4 million in the first attack and roughly $53.3 million in the second, which forced Uranium to shut down. Stolen funds were laundered through a series of crypto transactions including Tornado Cash and used to purchase rare Magic: The Gathering and Pokémon cards and antique Roman coins. Spalletta faces up to 10 years on the fraud count and 20 years on the money laundering count.
Domino's notified a small number of customers that their accounts were accessed by an unauthorized third party through credential stuffing — attackers using email-and-password pairs leaked in unrelated third-party breaches. Domino's confirmed its own systems were not compromised and that it does not store payment details, but it has reset affected accounts. The Operational Technology Cybersecurity Coalition published a proposal for a CISA Binding Operational Directive focused on OT at federal civilian agencies, noting those agencies rely on more than 8,000 GSA-managed facilities with HVAC, power management, access control, and building automation systems.
In Other News: what to watch
Raheim Hamilton, 30, of Virginia, received a 40-year prison sentence and a $5 million fine after pleading guilty to a drug conspiracy charge tied to Empire Market, the dark-web marketplace he co-created and operated with Thomas Pavey from 2018 to 2020. The site processed more than four million transactions worth over $430 million, primarily drug sales, alongside stolen credentials, counterfeit currency, and hacking tools. Pavey pleaded guilty last year and is scheduled for sentencing later this month, making October a significant moment for dark-web marketplace accountability.
On the standards and policy front, the OTCC's proposed CISA directive would require federal agencies to designate a senior official or office accountable for OT security, apply existing relevant requirements, and prioritize CISA's Cybersecurity Performance Goals. For Nvidia DCGM Exporter users, any deployment that exposes the service to the internet without authentication remains at risk until version 4.8.2 is installed. Organizations using the tensorlake npm SDK should audit whether version 0.5.144 was ever installed and rotate all credentials that could have been accessible during installation.
Developer Action Items
- ☐ Inventory whether AWS / Nvidia / GitHub runs in prod, CI, staging, or on laptops before you debate severity.
- ☐ Pull the vendor advisory for CVE-2026-47483 and patch from that page — not from a social recap.
- ☐ If you cannot patch today, isolate the service, rotate tokens that sat on the affected surface, and raise the logging floor.
- ☐ Record the decision and residual risk so the next on-call does not re-litigate whether you are exposed.
- ☐ Treat unexpected emails that mention AWS / Nvidia / GitHub (shipping, invoices, password resets) as phishing until verified.
In Other News FAQ
What is PoeLLM malware and how does its C&C mechanism work?
PoeLLM is a malware strain active since at least April 2026 that mines cryptocurrency and expands a botnet by targeting exposed AI services such as LiteLLM and Ollama. Infected machines extract four keywords from a GitHub-hosted poem and convert them into the IP address of the current command-and-control server, allowing the operator to rotate infrastructure by simply editing the poem.
What credentials does the tensorlake npm supply chain attack steal?
The compromised version 0.5.144 of the tensorlake npm SDK harvests npm, GitHub, AWS, Kubernetes, and Vault credentials, as well as AI coding tool configurations. It can also execute attacker-supplied code and republish itself through other packages the victim has publish rights to.
How should organizations fix CVE-2026-47483 in Nvidia DCGM Exporter?
Nvidia has patched the vulnerability; users should update the DCGM Exporter to version 4.8.2 or later. Any deployment currently exposing the profiling endpoints to the internet without authentication should be updated immediately or firewalled.
What sentence did Raheim Hamilton receive for running Empire Market?
Hamilton was sentenced to 40 years in prison and fined $5 million after pleading guilty to a drug conspiracy charge. Empire Market, which he co-ran with Thomas Pavey from 2018 to 2020, processed more than four million transactions worth over $430 million.
What evidence links AI tools to the South Korean bank cyberattacks?
CrowdStrike reported finding Claude Code session histories, ARTEX configuration files, and Claude memory files inside the attack infrastructure. South Korean President Lee Jae Myung stated publicly that signs point to AI being used in the attacks, and police have opened a full-scale investigation.
Sources
Author
Dillip Chowdary
Writes Tech Bytes coverage of AI, engineering, and the tools that actually ship. Editor of Tech Pulse Daily.
Related on Tech Bytes
9to5Mac Daily: October 9, 2026 – Apple’s ‘Welcome home’ launch announced, more
Read →
Apple acqui-hires AI startup founded by former NotebookLM developers
Read →
Android Bench 2 Adds Support for Long-Horizon Tasks, Agentic Evaluation, and Continuous…
Read →
The maker of non-text AI model Jev valued at $7.5B just weeks after launch
Read →
Today's Tech Pulse briefing
Full briefing →
Advertisement