Supply-chain attack using invisible code hits GitHub and other repositories
2026-03-13T20:51:56Z•7195fbbcde26d0cfe470e1e36a5ce3836c871da0bc0c2ae438bf39663bd853d2
airsnitchasustekbotnetcisacryptocurrency-theftdydxencryption-bypassgithubiosiot-securityknown-exploited-vulnerabilitiesmalicious-packagesmicrosoft-officenotepad++password-managersroutersrussian-actorssoftware-supply-chainstate-sponsoredstrykersupply-chainunicode-injectionupdate-compromisewifiwiper-attack
What happened
A cluster of active, high-impact incidents and emerging threats across software supply chains, infrastructure, and consumer devices. Notable stories include a Unicode-based supply-chain attack affecting GitHub and other repositories; a destructive wiper that knocked Stryker's Windows network offline; ~14,000 Asus routers infected with resilient malware; a Notepad++ update-server compromise used to deliver backdoors; malicious packages that drained dYdX wallets; rapid exploitation of a Microsoft Office flaw by Russian-state actors; CISA adding three iOS flaws to its known-exploited list; and a新
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- arstechnica_security
- Record identifier
- 7195fbbcde26d0cfe470e1e36a5ce3836c871da0bc0c2ae438bf39663bd853d2
- Enrichment time
- 2026-03-13T20:51:56Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.