
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
@byteplus/ark-cli
Advanced tools
BytePlus Ark command-line interface
BytePlus Ark CLI provides command-line access and Agent Skills for BytePlus Ark. This repository contains the public English Skills distributed with the CLI and the documentation required to use them from supported AI coding agents.
npm install -g @byteplus/ark-cli@latest
After installing the CLI, authenticate and install the bundled Skills into the supported local agents:
arkcli auth login
arkcli auth status
arkcli +connect
BytePlus CLI state is stored separately under ~/.arkcli-bp.
The skills/ directory contains one capability-oriented Skill per Ark CLI domain. Each Skill uses the standard SKILL.md and references/ layout and is written in English for BytePlus users.
The public Skill tree is derived from the Ark CLI source repository at a fixed commit. Product support is audited independently for BytePlus; the presence of a Skill documents the command surface and does not override the support status recorded by the product capability audit.
Scan the QR code to join the Ark CLI Lark user group for installation help, troubleshooting, bug reports, and usage discussions.
Do not share API keys, access keys, tokens, or other credentials in the group. For reproducible bugs, please also open a GitHub issue so the fix can be tracked.
Do not disclose security issues through a public GitHub issue or the user group. Report them through the official BytePlus support channel.
The public Skills and documentation are licensed under the Apache License 2.0.
FAQs
BytePlus Ark command-line interface
The npm package @byteplus/ark-cli receives a total of 0 weekly downloads. As such, @byteplus/ark-cli popularity was classified as not popular.
We found that @byteplus/ark-cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 30 open source maintainers collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.