ByteBrief
We're a portrait publication through and through. Turn your phone back and your briefing picks up right where you left it.
(We tried widescreen once. It wasn't us.)

Attackers compromised legitimate MemTensor packages on npm and PyPI, injecting a Go-based credential stealer called sckit. Malicious npm versions 0.1.21, 0.1.23, and 0.1.25, plus PyPI MemoryOS 2.0.34, launch the payload on import or agent start, harvesting tokens from npm, PyPI, GitHub, GitLab, AWS, Vault, and SSH. The npm packages remain available; pin to 0.1.20 or 2.0.33.
Tap to vote and see what everyone thinks.
Summary by ByteBrief