ByteBrief
We're a portrait publication through and through. Turn your phone back and your briefing picks up right where you left it.
(We tried widescreen once. It wasn't us.)

The npm package tensorlake was compromised on October 7, 2026, as part of a ChainDrop supply chain attack. Version 0.5.144 contains obfuscated malware that harvests credentials and exfiltrates secrets from local files, CI environments, and Kubernetes sources. The malicious code republishes itself and targets AI tools like Claude and Cursor to steal data from enterprises.
Tap to vote and see what everyone thinks.
Summary by ByteBrief