We use cookies

We use cookies to ensure you get the best experience on our website. For more information on how we use cookies, please see our cookie policy.

Back to home

Invisible malicious code attacks 151 GitHub repos and VS Code — Glassworm attack uses blockchain to steal tokens, credentials, and secrets

Source

Tom's Hardware

Published

TL;DR

AI Generated

Researchers at Aikido Security discovered that 151 GitHub repositories were infiltrated by Glassworm, a threat actor using invisible Unicode characters to hide malicious code. The attack, which started on March 3, has expanded to npm and the VS Code marketplace. The malicious code, when executed, can steal tokens, credentials, and secrets, with the payload using the Solana blockchain for command-and-control. Aikido advises caution when incorporating packages and suggests using automated tools to detect invisible Unicode injections.

Invisible malicious code attacks 151 GitHub repos and VS Code — Glassworm attack uses blockchain to steal tokens, credentials, and secrets - Tech News Aggregator