Re: Scientific American: Open Source infected with malware from invisible Unicode characters
Reini Urban via Unicode <[email protected]> Sun, 22 Mar 2026 10:27:25 +0100
| Newsgroups | gmane.text.unicode.general |
|---|---|
| Message-ID | <CAHiT=DFjBBM=nj+G0OXBFU8P71VyZmtHutkpudCuSYcfrw=XKA@mail.gmail.com> |
--000000000000ef03ab064d998623 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Not only Glassworm, previous attacks used the same. That's why I convinced rust to adopt TR39, implemented it by myself in cperl, made a libu8ident library, and filed a C and C++ proposal to adopt it. See https://github.com/rurban/libu8ident/tree/master/doc I also asked to github to add such checks into their UI, and implemented a binutils LD check for problematic names. It didnt make it into C++23 nor C++26 though, only MSVC and sdcc were supportive, gcc and clang not. They tried and failed to implement the simplier confusables checks, which are unusable for that. gcc also tried a very simple check I'm carrying in my gcc github. This would have detected it, but is a hack. Reini Urban Karl Williamson via Unicode <[email protected]> schrieb am So., 22. M=C3=A4rz 2026, 10:12: > Open-source software has an invisible vulnerability. Hackers have found i= t > A cybercrime campaign called GlassWorm is hiding malware in invisible > characters and spreading it through software that millions of developers > rely on The danger in the code came from characters that are invisible > to the human eye. In early March researchers at several security firms > examined what looked like empty space and found hidden Unicode > characters that decoded into a malicious program. Investigators soon > traced hundreds of compromised open-source components spread across > GitHub, npm and > > Read in Scientific American: https://apple.news/ACCjFPpifQlCNSMetYCJ2Dg > --000000000000ef03ab064d998623 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"auto"><div><div>Not only Glassworm, previous attacks used the s= ame.=C2=A0</div><div dir=3D"auto">That's why I convinced rust to adopt = TR39, implemented it by myself in cperl, made a libu8ident library, and fil= ed a C and C++ proposal to adopt it. See <a href=3D"https://github.com/rurb= an/libu8ident/tree/master/doc">https://github.com/rurban/libu8ident/tree/ma= ster/doc</a></div><div dir=3D"auto">I also asked to github to add such chec= ks into their UI, and implemented a binutils LD check for problematic names= .=C2=A0</div><div dir=3D"auto"><br></div><div dir=3D"auto">It didnt make it= into C++23 nor C++26=C2=A0 though, only MSVC and sdcc were supportive, gcc= and clang not. They tried and failed to implement the simplier confusables= checks, which are unusable for that. gcc also tried a very simple check I&= #39;m carrying in my gcc github. This would have detected it, but is a hack= .=C2=A0</div><div><br></div><div data-smartmail=3D"gmail_signature"><div di= r=3D"ltr"><div>Reini Urban<br></div></div></div><br><div class=3D"gmail_quo= te gmail_quote_container"><div dir=3D"ltr" class=3D"gmail_attr">Karl Willia= mson via Unicode <<a href=3D"mailto:[email protected]">unicode@co= rp.unicode.org</a>> schrieb am So., 22. M=C3=A4rz 2026, 10:12:<br></div>= <blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-= left:1px solid rgb(204,204,204);padding-left:1ex">Open-source software has = an invisible vulnerability. Hackers have found it<br> A cybercrime campaign called GlassWorm is hiding malware in invisible <br> characters and spreading it through software that millions of developers <b= r> rely on The danger in the code came from characters that are invisible <br> to the human eye. In early March researchers at several security firms <br> examined what looked like empty space and found hidden Unicode <br> characters that decoded into a malicious program. Investigators soon <br> traced hundreds of compromised open-source components spread across <br> GitHub, npm and<br> <br> Read in Scientific American: <a href=3D"https://apple.news/ACCjFPpifQlCNSMe= tYCJ2Dg" rel=3D"noreferrer noreferrer" target=3D"_blank">https://apple.news= /ACCjFPpifQlCNSMetYCJ2Dg</a><br> </blockquote></div></div></div> --000000000000ef03ab064d998623--