logo

The Return of the Invisible Threat: Hidden PUA Unicode Hits GitHub repositorties

ID: 024aa0f7-7337-5d85-bbad-741239d02a5b

STIX ID: report--024aa0f7-7337-5d85-bbad-741239d02a5b

Feed Name: Aikido Security's Blog

Threat Score
75/100

Date Published: 2025-10-31

Date Updated: 2026-07-24

...
...

Aikido describes a campaign where attackers hide malicious JavaScript in invisible Unicode Private Use Area characters appended to otherwise legitimate-looking GitHub commits; the payload (Glassworm) uses Solana as a delivery channel to fetch and execute code that can steal tokens and credentials, and the technique builds on earlier npm and Open VSX supply-chain compromises while evolving to be more stealthy (single-line obfuscation, likely AI-generated commit content).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.