Glassworm has hit 400+ repos across GitHub, npm, and VS Code using invisible Unicode characters to encode executable payloads that pass every code review, linter, and AI assistant.Vibe Check is a browser-based scanner that detects these characters across 14 invisible Unicode ranges (zero-width spaces, variation selectors supplement, tag characters, bidi overrides, etc.) and flags sequences of 3+ consecutive invisible characters as likely payloads. Entirely client-side JS — no code leaves your browser.Not a full SAST tool. Solves one specific problem: detecting characters that are invisible in every editor and terminal but can encode payloads decoded via eval() at runtime.Scanner logic is in scanner.js, viewable in browser. Site runs on Cloudflare Pages free tier.https://websationflow.com Comments URL: https://news.ycombinator.com/item?id=47917600 Points: 1 # Comments: 0
Want to discover more AI signals like this?
Explore Steek