Re: Scientific American: Open Source infected with malware from invisible Unicode characters

Reini Urban via Unicode <[email protected]> Sun, 22 Mar 2026 10:27:25 +0100
Newsgroups gmane.text.unicode.general
Message-ID <CAHiT=DFjBBM=nj+G0OXBFU8P71VyZmtHutkpudCuSYcfrw=XKA@mail.gmail.com>
--000000000000ef03ab064d998623
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Not only Glassworm, previous attacks used the same.
That's why I convinced rust to adopt TR39, implemented it by myself in
cperl, made a libu8ident library, and filed a C and C++ proposal to adopt
it. See https://github.com/rurban/libu8ident/tree/master/doc
I also asked to github to add such checks into their UI, and implemented a
binutils LD check for problematic names.

It didnt make it into C++23 nor C++26  though, only MSVC and sdcc were
supportive, gcc and clang not. They tried and failed to implement the
simplier confusables checks, which are unusable for that. gcc also tried a
very simple check I'm carrying in my gcc github. This would have detected
it, but is a hack.

Reini Urban

Karl Williamson via Unicode <[email protected]> schrieb am So., 22.
M=C3=A4rz 2026, 10:12:

> Open-source software has an invisible vulnerability. Hackers have found i=
t
> A cybercrime campaign called GlassWorm is hiding malware in invisible
> characters and spreading it through software that millions of developers
> rely on The danger in the code came from characters that are invisible
> to the human eye. In early March researchers at several security firms
> examined what looked like empty space and found hidden Unicode
> characters that decoded into a malicious program. Investigators soon
> traced hundreds of compromised open-source components spread across
> GitHub, npm and
>
> Read in Scientific American: https://apple.news/ACCjFPpifQlCNSMetYCJ2Dg
>

--000000000000ef03ab064d998623
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"auto"><div><div>Not only Glassworm, previous attacks used the s=
ame.=C2=A0</div><div dir=3D"auto">That&#39;s why I convinced rust to adopt =
TR39, implemented it by myself in cperl, made a libu8ident library, and fil=
ed a C and C++ proposal to adopt it. See <a href=3D"https://github.com/rurb=
an/libu8ident/tree/master/doc">https://github.com/rurban/libu8ident/tree/ma=
ster/doc</a></div><div dir=3D"auto">I also asked to github to add such chec=
ks into their UI, and implemented a binutils LD check for problematic names=
.=C2=A0</div><div dir=3D"auto"><br></div><div dir=3D"auto">It didnt make it=
 into C++23 nor C++26=C2=A0 though, only MSVC and sdcc were supportive, gcc=
 and clang not. They tried and failed to implement the simplier confusables=
 checks, which are unusable for that. gcc also tried a very simple check I&=
#39;m carrying in my gcc github. This would have detected it, but is a hack=
.=C2=A0</div><div><br></div><div data-smartmail=3D"gmail_signature"><div di=
r=3D"ltr"><div>Reini Urban<br></div></div></div><br><div class=3D"gmail_quo=
te gmail_quote_container"><div dir=3D"ltr" class=3D"gmail_attr">Karl Willia=
mson via Unicode &lt;<a href=3D"mailto:[email protected]">unicode@co=
rp.unicode.org</a>&gt; schrieb am So., 22. M=C3=A4rz 2026, 10:12:<br></div>=
<blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-=
left:1px solid rgb(204,204,204);padding-left:1ex">Open-source software has =
an invisible vulnerability. Hackers have found it<br>
A cybercrime campaign called GlassWorm is hiding malware in invisible <br>
characters and spreading it through software that millions of developers <b=
r>
rely on The danger in the code came from characters that are invisible <br>
to the human eye. In early March researchers at several security firms <br>
examined what looked like empty space and found hidden Unicode <br>
characters that decoded into a malicious program. Investigators soon <br>
traced hundreds of compromised open-source components spread across <br>
GitHub, npm and<br>
<br>
Read in Scientific American: <a href=3D"https://apple.news/ACCjFPpifQlCNSMe=
tYCJ2Dg" rel=3D"noreferrer noreferrer" target=3D"_blank">https://apple.news=
/ACCjFPpifQlCNSMetYCJ2Dg</a><br>
</blockquote></div></div></div>

--000000000000ef03ab064d998623--