Supply-chain attack using invisible code hits GitHub and other repositories

2026-03-13T20:51:56Z7195fbbcde26d0cfe470e1e36a5ce3836c871da0bc0c2ae438bf39663bd853d2
airsnitchasustekbotnetcisacryptocurrency-theftdydxencryption-bypassgithubiosiot-securityknown-exploited-vulnerabilitiesmalicious-packagesmicrosoft-officenotepad++password-managersroutersrussian-actorssoftware-supply-chainstate-sponsoredstrykersupply-chainunicode-injectionupdate-compromisewifiwiper-attack

What happened

A cluster of active, high-impact incidents and emerging threats across software supply chains, infrastructure, and consumer devices. Notable stories include a Unicode-based supply-chain attack affecting GitHub and other repositories; a destructive wiper that knocked Stryker's Windows network offline; ~14,000 Asus routers infected with resilient malware; a Notepad++ update-server compromise used to deliver backdoors; malicious packages that drained dYdX wallets; rapid exploitation of a Microsoft Office flaw by Russian-state actors; CISA adding three iOS flaws to its known-exploited list; and a新

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arstechnica_security
Record identifier
7195fbbcde26d0cfe470e1e36a5ce3836c871da0bc0c2ae438bf39663bd853d2
Enrichment time
2026-03-13T20:51:56Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Supply-chain attack using invisible code hits GitHub and other repositories · Baitaphish