Aw: Re: Scientific American: Open Source infected with malware from invisible Unicode characters
Marius Spix via Unicode <[email protected]> Tue, 24 Mar 2026 11:21:22 +0000
| Newsgroups | gmane.text.unicode.general |
|---|---|
| Message-ID | <trinity-661591dd-7b58-4ad9-8433-57caa21d2973-1774351282822@trinity-msg-rest-webde-webde-live-6867c796b7-zmnnt> |
<html><body><div style=3D"font-family: 'verdana'; font-size: 12px; color: #=
000;"><span style=3D"background-color: #ffffff;">That's the reason why open=
source projects should always implement a linter check in their code-revie=
w pipeline, which scans for unusual usage of invisible characters=2E This i=
ncludes non-code files like documentation or test cases, because they can a=
lso be abused (as seen in the XZ toolchain attack)=2E</span></div>
<div id=3D"sub-body-container" style=3D"margin: 10px 5px 5px 10px; padding=
: 10px 0px 10px 10px; border-left: 2px solid rgb(195, 217, 229);">
<div style=3D"margin: 0px 0px 10px;">
<div><strong>Gesendet: </strong>Dienstag, 24=2E M=C3=A4rz 2026 um 06:39</d=
iv>
<div><strong>Von: </strong>"Martin J=2E D=C3=BCrst via Unicode" <unicod=
e@corp=2Eunicode=2Eorg></div>
<div><strong>An: </strong>"Nitai Sasson" <unicode=2Eorg@sl=2Eneatnit=2E=
net>, "Karl Williamson" <public@khwilliamson=2Ecom></div>
<div><strong>CC: </strong>"unicode@corp=2Eunicode=2Eorg" <unicode@corp=
=2Eunicode=2Eorg></div>
<div><strong>Betreff: </strong>Re: Scientific American: Open Source infect=
ed with malware from invisible Unicode characters</div>
</div>
The interesting thing is that Koi (a security firm) talked about the <br>G=
lassWorm attack already on October 18, 2025, but the Scientific <br>America=
n article is from March 21, 2026=2E Apparently the original report <br>didn=
't get enough publicity=2E<br><br>Regards, Martin=2E<br><br>On 2026-03-23 0=
7:37, Nitai Sasson via Unicode wrote:<br>> Thank you for sharing, this i=
s quite interesting=2E I tried to find examples of how this actually works=
=2E Found this article: <a href=3D"https://www=2Ekoi=2Eai/blog/glassworm-fi=
rst-self-propagating-worm-using-invisible-code-hits-openvsx-marketplace" ta=
rget=3D"_blank" rel=3D"noopener noreferrer">https://www=2Ekoi=2Eai/blog/gla=
ssworm-first-self-propagating-worm-using-invisible-code-hits-openvsx-market=
place</a><br>> <br>> The screenshot in it shows a clearly suspicious =
line of code: var decodedBytes =3D decode(' =2E=2E=2E a very long invisible=
string =2E=2E=2E ');<br>> <br>> So yes, the string is invisible, but=
it's not in itself executable=2E It needs to be decoded using a small amou=
nt of normal, visible and very suspicious code=2E So the claim that the vul=
nerability is invisible and can't be caught by normal code review seems a b=
it disingenuous=2E It's just a new way to obfuscate a string=2E<br>> <br=
>> I haven't found any other description of what compromised source code=
looks like in practice=2E So best I can tell, while this is really interes=
ting, it's not as undetectable to the naked eye as it sounds=2E<br>> <br=
>> Still, very interesting! And if anyone has information that I haven't=
found, please share=2E Any technical dive into it would likely be a good r=
ead=2E<br>> <br>> - Nitai<br>> <br>> -------- Original Message =
--------<br>> On Sunday, 03/22/26 at 11:12 Karl Williamson via Unicode &=
lt;unicode@corp=2Eunicode=2Eorg> wrote:<br>> Open-source software has=
an invisible vulnerability=2E Hackers have found it<br>> A cybercrime c=
ampaign called GlassWorm is hiding malware in invisible<br>> characters =
and spreading it through software that millions of developers<br>> rely =
on The danger in the code came from characters that are invisible<br>> t=
o the human eye=2E In early March researchers at several security firms<br>=
> examined what looked like empty space and found hidden Unicode<br>>=
characters that decoded into a malicious program=2E Investigators soon<br>=
> traced hundreds of compromised open-source components spread across<br=
>> GitHub, npm and<br>> <br>> Read in Scientific American: <a href=
=3D"https://apple=2Enews/ACCjFPpifQlCNSMetYCJ2Dg" target=3D"_blank" rel=3D"=
noopener noreferrer">https://apple=2Enews/ACCjFPpifQlCNSMetYCJ2Dg</a><br><b=
r></div></body></html>