ByteBrief
We're a portrait publication through and through. Turn your phone back and your briefing picks up right where you left it.
(We tried widescreen once. It wasn't us.)

Upwind Security first reported that [email protected], an npm package with 154 million weekly downloads, contained a malicious preinstall script harvesting AWS credentials, GitHub tokens, npm auth tokens, and HashiCorp Vault secrets. The campaign expanded to 16 packages across two ecosystems, scoring 92 overall in Upwind's Combined Incident Report.
Tracked by ByteBrief