Invisible Unicode Malware Strikes OpenVSX, Again

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

A threat actor that Aikido Security has been tracking since March has compromised three more Open VSX extensions using invisible non-printable Unicode characters: adhamu/history-in-sublime-merge, yasuyuky/transient-emacs, and ai-driven-dev/ai-driven-dev. This follows a security update from the Eclipse Foundation on October

2m read timeFrom aikido.dev
Post cover image
Table of contents
Open VSX October 27th updateAn ongoing saga

Sort: