Glassworm Is Back: A New Wave of Invisible Unicode Attacks Hits Hundreds of Repositories
ID: f915bddd-f129-596d-af66-9aa390a53b94
STIX ID: report--f915bddd-f129-596d-af66-9aa390a53b94
Feed Name: Aikido Security's Blog
Threat Score
Aikido reports a renewed Glassworm campaign (March 2026) that uses invisible Unicode characters embedded in code strings to hide a decoder which evals a payload; the campaign has compromised hundreds of GitHub repositories and expanded to npm and the VS Code marketplace, with affected packages and extensions identified and prior behavior indicating second-stage payloads capable of stealing tokens, credentials, and secrets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
