Unicode Tricks Let Malicious Python Code Bypass Code Review
A subtle but powerful class of attacks allows source code to pass human review while executing completely different logic. The root cause lies in the gap between how fonts render Unicode characters and how the Python interpreter reads the underlying bytes.
The first technique uses homoglyphs. An attacker can declare is_admin = False followed by a second assignment that looks identical but actually uses the Ukrainian letter і (U+0456) instead of Latin i (U+0069). The review sees a single variable being set to True, yet the interpreter creates two separate identifiers. The same substitution works for function names such as validate_token, causing the wrong implementation to run in production.
Python normalizes identifiers with NFKC, which collapses some visually similar characters but leaves Cyrillic letters untouched. Consequently, the attack remains effective in real codebases.
The second technique relies on bidirectional override characters (RIGHT-TO-LEFT OVERRIDE U+202E and related controls). These characters are required for Arabic and Hebrew text, yet they also allow an attacker to reorder source lines visually. A comment that appears harmless on screen can actually contain executable statements once the compiler ignores the display order. The technique became widely known in 2021 as the Trojan Source attack and affects nearly every mainstream programming language.
The third, simpler method inserts zero-width characters (U+200B, U+2060, etc.) inside string literals. The string 'password' has length nine and will never equal the expected value, yet the difference is invisible to the naked eye and defeats both manual inspection and simple grep searches.
A compact detection script walks the source with Python’s tokenize module and separately scans for bidirectional and zero-width characters. Checking only identifier tokens prevents false positives from comments and string data. The same logic is available as built-in rules in ruff and flake8, while gitleaks can block commits containing the dangerous characters.
Teams are advised to run the check across existing repositories, integrate it into CI pipelines, and treat any intentional insertion of these characters as a serious red flag during incident review.
Related articles
redb 3.7.2 Released with Custom gRPC Protocol, Dependency Vulnerability Fixes and .NET 10 Migration
The redb ecosystem released versions 3.7.0, 3.7.1 and 3.7.2 in quick succession after 3.7.0 was withdrawn due to high-severity vulnerabilities in its .NET 9 build artifacts. NuGet audit detected issues only on full rebuilds, leading to updates for SSH.NET, Microsoft.Data.Sqlite, System.Security.Cryptography.Xml and Microsoft.Bcl.Memory across redb.Route, redb.Core, redb.Export and redb.Identity. The release introduces a native GrpcWire implementation that registers individual gRPC methods as routes on a shared Kestrel host, supports bidirectional streaming, real gRPC status codes and mTLS with pinned client certificates. redb.Route also gained a dedicated SOAP connector, Control Bus messaging for route lifecycle management and a corrected Claim Check pattern. File transports received critical fixes that prevent silent data loss when readLock and idempotency options are combined. All libraries now target net8.0;net9.0;net10.0 while host applications require .NET 10, aligning with Microsoft’s shortened support timeline for .NET 8 and 9.
Poisoned Rust Crates Execute Malware at Build Time: 245 Million Downloads Hit in Supply-Chain Attack
Three widely used Rust crates on crates.io were poisoned on August 20 with malicious versions that execute automatically during cargo build. The attack leveraged a typosquatted proc-macro1 dependency containing a build script that downloads payloads and establishes persistence. arrayref alone has accumulated 245 million downloads and is pulled automatically through caret ranges in many dependency trees. Attack infrastructure overlaps with prior campaigns attributed to Sapphire Sleet and MIDNIGHT NEPTUNE. Rust security teams yanked the malicious releases within 86-107 minutes, but the incident highlights missing publish-age controls and weak maintainer-account protections in the Cargo ecosystem.
PyPI Explores Prefix Reservation for Organizations Under PEP 752 to Prevent Name Squatting
PEP 752 proposes reserving package name prefixes for organizations on PyPI, allowing control over entire families of related package names rather than individual entries. The change addresses dependency confusion and name squatting risks where attackers register packages with familiar prefixes like google-cloud- or opentelemetry- to exploit user trust. Analysis of over 800,000 PyPI projects by CodeScoring shows that prefixes are rarely controlled by a single owner, with ecosystems like aws- managed by hundreds of accounts. The proposal introduces implicit namespaces and new metadata for clients and proxies while preserving the flat namespace model familiar to Python developers. PEP 755 will define the governance process for granting prefix rights, limiting applications to organizations and requiring clear justification. Existing packages receive backward compatibility exceptions, and the mechanism does not transfer across repositories.
Suspicious Certificate Issuer Detected in MAX Messenger Windows Update Package
A detailed observation from a security researcher highlights an unexpected change in the code signing certificate for the MAX messenger desktop client on Windows. The August update package was signed by an individual named Konstantin Syomochkin instead of the usual Communication Platform LLC. This discrepancy raised concerns about potential supply chain interference linked to recent EU sanctions against the developer. The certificate was issued shortly after sanctions and belongs to a person based in Astana, Kazakhstan, with limited public ties to the VK team. Official MSI installers downloaded directly from the MAX website remain signed by the company, while the client-triggered update differs in both version and signer. The researcher recommends that VK verify the download chain through Mail.ru trackers to rule out tampering. Installation of the update was declined pending further clarification.