Security experts from Aikido Security have uncovered a concerning supply-chain attack that has affected numerous repositories, including GitHub. Between March 3 and March 9, they identified 151 malicious packages that were uploaded. These types of attacks have been prevalent for years, typically involving the distribution of harmful packages that mimic the names and functionalities of legitimate libraries, tricking developers into integrating them into their projects. In some instances, these malicious packages have been downloaded thousands of times. The latest attack, however, employs a more sophisticated method: it utilizes invisible code that remains undetectable in most code editors and review tools. While the visible code appears normal, the harmful elements are encoded in unicode characters that are not perceivable to the naked eye. This innovative approach, first noted by Aikido last year, significantly undermines traditional security measures, rendering them ineffective. Other platforms affected by this attack include NPM and Open VSX.
Invisible Code Supply-Chain Attack Targets GitHub and Other Repositories
A recent supply-chain attack has been identified, involving malicious packages with invisible code that evade standard detection methods.
