unicode-obfuscation

1 article
sort: new top best
clear filter
0 6/10

Researchers discovered 151 malicious packages using invisible Unicode characters to hide executable code in repositories including GitHub and npm. The technique leverages Public Use Area characters that appear as whitespace to humans but execute as code at runtime, making traditional code reviews ineffective and suspected to be AI-generated at scale.

Aikido Security Glassworm Koi GitHub npm Open VSX VS Code Solana Dan Goodin
arstechnica.com · joozio · 6 hours ago · details · hn