Supply-chain attack using invisible code hits GitHub and other repositories
2026-03-16T08:51:53Z•8936b554fdf286b41fdd4b2ad1ad6eacc502e2e2b9ed91d81c56d7b74413edcb
AirSnitchAsusCISAIranLumma-StealerNotepad++Strykerbotnetcertificate-expiry`,`LLM-deanonymization`,`ai-prompts`,`child-uxcryptocurrency-theftgithubiOS-exploitsinvisible-unicodeiotmalicious-packagesoffice-zero-daypassword-managersrouterssecure-bootsecurity-camerassoftware-supply-chainstate-sponsoredsupply-chainwifiwiper
What happened
A March 2026 Ars Technica security roundup highlights a wave of high-impact incidents: a supply‑chain vector using invisible Unicode code affecting GitHub and other repos; a destructive wiper that has taken Stryker's Windows environment offline; ~14,000 Asus and other routers infected by resilient malware; state-linked campaigns targeting consumer security cameras; and CISA additions of multiple exploited iOS vulnerabilities. Other notable items include an AirSnitch Wi‑Fi encryption bypass, resurgence of Lumma Stealer and malicious packages that drained dYdX wallets, a Notepad++ updater supply
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- arstechnica_security
- Record identifier
- 8936b554fdf286b41fdd4b2ad1ad6eacc502e2e2b9ed91d81c56d7b74413edcb
- Enrichment time
- 2026-03-16T08:51:53Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.