ByteBrief
We're a portrait publication through and through. Turn your phone back and your briefing picks up right where you left it.
(We tried widescreen once. It wasn't us.)

Upwind first reported malicious [email protected], an npm package with 154 million weekly downloads, containing a preinstall script that harvested AWS credentials, GitHub tokens, and npm auth tokens. The campaign expanded to hundreds of packages. Upwind advises removing the compromised version, rotating credentials, and auditing lockfiles.
Tap to vote and see what everyone thinks.
Summary by ByteBrief