• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
TechTrendFeed
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
TechTrendFeed
No Result
View All Result

Provide-chain assault utilizing invisible code hits GitHub and different repositories

Admin by Admin
March 16, 2026
Home Tech News
Share on FacebookShare on Twitter



Researchers say they’ve found a supply-chain assault flooding repositories with malicious packages that comprise invisible code, a method that’s flummoxing conventional defenses designed to detect such threats.

The researchers, from agency Aikido Safety, mentioned Friday that they discovered 151 malicious packages that had been uploaded to GitHub from March 3 to March 9. Such supply-chain assaults have been widespread for almost a decade. They often work by importing malicious packages with code and names that carefully resemble these of extensively used code libraries, with the target of tricking builders into mistakenly incorporating the previous into their software program. In some instances, these malicious packages are downloaded hundreds of instances.

Defenses see nothing. Decoders see executable code

The packages Aikido discovered this month have adopted a more recent method: selective use of code that isn’t seen when loaded into just about all editors, terminals, and code evaluate interfaces. Whereas many of the code seems in regular, readable type, malicious features and payloads—the same old telltale indicators of malice—are rendered in unicode characters which are invisible to the human eye. The tactic, which Aikido mentioned it first noticed final 12 months, makes handbook code evaluations and different conventional defenses almost ineffective. Different repositories hit in these assaults embody NPM and Open VSX.

Learn full article

Feedback

Tags: AttackCodeGitHubHitsinvisiblerepositoriesSupplychain
Admin

Admin

Next Post
OpenClaw AI Agent Flaws May Allow Immediate Injection and Knowledge Exfiltration

OpenClaw AI Agent Flaws May Allow Immediate Injection and Knowledge Exfiltration

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Trending.

Reconeyez Launches New Web site | SDM Journal

Reconeyez Launches New Web site | SDM Journal

May 15, 2025
Safety Amplified: Audio’s Affect Speaks Volumes About Preventive Safety

Safety Amplified: Audio’s Affect Speaks Volumes About Preventive Safety

May 18, 2025
Apollo joins the Works With House Assistant Program

Apollo joins the Works With House Assistant Program

May 17, 2025
Discover Vibrant Spring 2025 Kitchen Decor Colours and Equipment – Chefio

Discover Vibrant Spring 2025 Kitchen Decor Colours and Equipment – Chefio

May 17, 2025
Flip Your Toilet Right into a Good Oasis

Flip Your Toilet Right into a Good Oasis

May 15, 2025

TechTrendFeed

Welcome to TechTrendFeed, your go-to source for the latest news and insights from the world of technology. Our mission is to bring you the most relevant and up-to-date information on everything tech-related, from machine learning and artificial intelligence to cybersecurity, gaming, and the exciting world of smart home technology and IoT.

Categories

  • Cybersecurity
  • Gaming
  • Machine Learning
  • Smart Home & IoT
  • Software
  • Tech News

Recent News

Oracle EBS Hack: Solely 4 Company Giants Nonetheless Silent on Potential Affect

Oracle EBS Hack: Solely 4 Company Giants Nonetheless Silent on Potential Affect

March 16, 2026
Prime 7 Free Machine Studying Programs with Certificates

Prime 7 Free Machine Studying Programs with Certificates

March 16, 2026
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://techtrendfeed.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT

© 2025 https://techtrendfeed.com/ - All Rights Reserved