
aikido.dev
March 15, 2026
4 min read
62/100
Summary
Glassworm malware has re-emerged, compromising over 150 GitHub repositories, npm, and VS Code through the use of hidden Unicode characters. This resurgence follows previous activity traced back to the same threat actor, highlighting ongoing vulnerabilities in these platforms.
Key Takeaways
Community Sentiment
Concerns

Config Files That Run Code: Supply Chain Security Blindspot
Jun 8, 2026

Keyv and friends compromised in active Shai-Hulud supply chain attack
Aug 4, 2026

Shai-Hulud Themed Malware Found in the PyTorch Lightning AI Training Library
Apr 30, 2026

Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware
Aug 7, 2026

I found 10k GitHub repositories distributing Trojan malware
Jun 18, 2026