The Return of the Invisible Threat: Hidden PUA Unicode Hits GitHub repositorties
aikido.dev | blog | #supply-chain | #malware | #github | #npm | #open-vsx | #glassworm | #pua-unicode
Summary
Aikido tracked one threat actor from npm and Open VSX to GitHub: commits with null emails hide payloads in invisible PUA Unicode, executed via eval within seemingly legitimate feature updates.
- Published
- Collected
Skip to content