Cybersecurity
GitHub: Invisible Unicode Supply‑Chain Campaign Encodes Malicious JavaScript
Researchers uncovered a cross‑registry campaign that hides executable JavaScript inside seemingly blank strings by using invisible Unicode code points, prompting removals across GitHub, npm, and the VS Code Marketplace. Related investigations link the tactic to publisher‑account abuses, off‑platform Solana memo signaling, and platform convenience features (Codespaces) and package manager gaps that together magnify supply‑chain risk and demand coordinated registry and toolchain fixes.