
Researchers at Aikido Security reported on Friday that they had found at least 151 GitHub repositories compromised by a threat actor tracked as Glassworm, which hides malicious payloads in Unicode characters invisible to the human eye. The affected repositories were compromised between March 3 and March 9, according to the Aikido Security blog, and the campaign has since expanded to npm and the VS Code marketplace.
Go deeper with TH Premium: CPU
