"Rather than inserting logical bugs, adversaries can attack the encoding of source code files to inject vulnerabilities.

These adversarial encodings produce no visual artifacts.

The trick is to use Unicode control characters to reorder tokens in source code at the encoding level."

trojansource.codes/

0

If you have a fediverse account, you can quote this note from your own instance. Search https://infosec.exchange/users/sleepycat/statuses/115957830465129528 on your instance and quote it. (Note that quoting is not supported in Mastodon.)