Glassworm Returns: Invisible Unicode Attacks Targeting GitHub, npm, and VS Code Extensions
Aikido Security Blog·high signal
Aikido Security disclosed a new wave of Glassworm-style attacks using invisible Unicode characters to hide malicious code in GitHub repositories, npm packages, and VS Code extensions — precisely the toolchain used by AI coding agents. These attacks are particularly dangerous in AI-generated code pipelines where developers review less carefully. 60pts and 14 comments on HN confirms security practitioner attention.