ByteBrief
We're a portrait publication through and through. Turn your phone back and your briefing picks up right where you left it.
(We tried widescreen once. It wasn't us.)

Upwind Security first reported a deceptive npm compromise exploiting install scripts, not vulnerabilities. The keyv campaign drew about 154 million weekly downloads and scored 92 overall. Sixteen packages across two ecosystems were affected, targeting AWS credentials, GitHub tokens, npm registry credentials, and HashiCorp Vault tokens.
Tap to vote and see what everyone thinks.
Summary by ByteBrief
npm Worm Poisons Hundreds of Packages