Researchers found 151 malicious packages uploaded to repositories like GitHub, npm, and Open VSX that hide harmful code using invisible Unicode characters, making the malware undetectable in normal editors and code reviews. via Ars Technica arstechnica.com/security/202...
Supply-chain attack using invisible code hits GitHub and other repositories
Unicode that's invisible to the human eye was largely abandoned—until attackers took notice.
arstechnica.com