The Glassworm campaign has compromised over 151 GitHub repositories and npm packages using invisible Unicode payloads that evade standard code review.
The infamous GlassWorm malware has infected dozens more Open VSX software packages, according to new research.
How can an extension change hands with no oversight?