GlassWorm: First Self-Propagating Worm Using Invisible Code Hits OpenVSX Marketplace

7 points by soulcutter


kevinmehall

I wish they could just report the facts instead of the overly dramatic "malware is invisible"..."completely breaks traditional code review" nonsense.

You can see the decode('...') and eval(atob(decodedString)) just fine, and that's a giant red flag whether the stuff in the quotes looks like whitespace or base64.

bcd

Important story, horrible presentation.

fanf

previously…

Whitespace is a particularly useful language for spies. Imagine you have a top secret program that you don't want anyone to see…