Researchers discovered 151 malicious packages using invisible Unicode characters to hide executable code in repositories including GitHub and npm. The technique leverages Public Use Area characters that appear as whitespace to humans but execute as code at runtime, making traditional code reviews ineffective and suspected to be AI-generated at scale.
Slopoly, an AI-generated malware strain, was used in an Interlock ransomware attack to maintain persistence on a compromised server for over a week and exfiltrate data.
Researchers disclosed Slopoly, an AI-assisted malware framework used by the financially motivated threat actor Hive0163 to establish persistent access for ransomware attacks, demonstrating how threat actors are leveraging AI to rapidly develop malware.