Tensorlake npm SDK 0.5.144 was compromised in a ChainDrop supply chain attack, delivering an obfuscated credential-stealing ...