
Hidden Malware Found in 433 Open-Source Software Programs
CrowdStrike, Google, and Shadowserver shut down a botnet in May 2026 that had infected 433 free software packages. The attackers hid malicious code using invisible characters—text that appears blank to the human eye but remains active in the software. This marks a serious escalation in how hackers target shared code that millions of developers rely on.
Published