Supply-chain attack using invisible code hits GitHub and other repositories

2026-03-16T20:51:57Z994bef1aff2fd2167f1b40ff610af1d1b4d3a2e3a69bdcace566e9252d597b79
airsnitchasuscastleloadercertificate-expirycisadydx-malicious-package','crypto-theft','office-exploit','russianencryption-bypassios-exploitsiot-compromiseiranian-actorsknown-exploited-vulnerabilitiesllm-deanonymizationlumma-stealerpassword-manager-riskprivacyrepository-malwarerouter-botnetsecure-boot-certificatessecurity-camerasstrykersupply-chainsupply-chain-compromiseunicode-homographwifi-bypasswiper

What happened

A cluster of high-impact security incidents and trends: attackers are abusing invisible Unicode (homograph) techniques to introduce malicious code into software repositories; a destructive wiper has disrupted Stryker's Windows network; ~14,000 mostly Asus routers are infected with resilient malware; apparent Iran-linked actors are hijacking consumer security cameras; CISA added multiple iOS flaws to its known-exploited catalog; LLMs can deanonymize pseudonymous users at scale; a new “AirSnitch” technique undermines Wi‑Fi encryption; password-manager server compromises and malicious package/CI/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arstechnica_security
Record identifier
994bef1aff2fd2167f1b40ff610af1d1b4d3a2e3a69bdcace566e9252d597b79
Enrichment time
2026-03-16T20:51:57Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Supply-chain attack using invisible code hits GitHub and other repositories · Baitaphish