Supply-chain attack using invisible code hits GitHub and other repositories
2026-03-16T20:51:57Z•994bef1aff2fd2167f1b40ff610af1d1b4d3a2e3a69bdcace566e9252d597b79
airsnitchasuscastleloadercertificate-expirycisadydx-malicious-package','crypto-theft','office-exploit','russianencryption-bypassios-exploitsiot-compromiseiranian-actorsknown-exploited-vulnerabilitiesllm-deanonymizationlumma-stealerpassword-manager-riskprivacyrepository-malwarerouter-botnetsecure-boot-certificatessecurity-camerasstrykersupply-chainsupply-chain-compromiseunicode-homographwifi-bypasswiper
What happened
A cluster of high-impact security incidents and trends: attackers are abusing invisible Unicode (homograph) techniques to introduce malicious code into software repositories; a destructive wiper has disrupted Stryker's Windows network; ~14,000 mostly Asus routers are infected with resilient malware; apparent Iran-linked actors are hijacking consumer security cameras; CISA added multiple iOS flaws to its known-exploited catalog; LLMs can deanonymize pseudonymous users at scale; a new “AirSnitch” technique undermines Wi‑Fi encryption; password-manager server compromises and malicious package/CI/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- arstechnica_security
- Record identifier
- 994bef1aff2fd2167f1b40ff610af1d1b4d3a2e3a69bdcace566e9252d597b79
- Enrichment time
- 2026-03-16T20:51:57Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.