Skip to content
AI IntelligenceMar 15, 2026AI Intelligence
Article

A new attack dubbed 'Glassworm' uses invisible Unicode characters to compromise GitHub repositories, npm packages, and VS Code.

It's a new wave of activity from the same threat actor responsible for similar attacks last year.

Data Cube AI EditorialSource: Hacker News
01

Source Brief

A new attack dubbed 'Glassworm' uses invisible Unicode characters to compromise GitHub repositories, npm packages, and VS Code. It's a new wave of activity from the same threat actor responsible for similar attacks last year.