Glassworm Is Back: Invisible Unicode Attacks Hit GitHub and npm

1 min read

A new wave of supply chain attacks uses invisible Unicode characters to hide malicious code in GitHub repos, npm packages, and VS Code extensions. The technique evades visual code review entirely.

// share this

// get daily digest

Top 10 dev stories every morning at 8am UTC. AI-curated. Retro terminal HTML email.