Tom's Hardware
Invisible malicious code attacks 151 GitHub repos and VS Code — Glassworm attack uses blockchain to steal tokens, credentials, and secrets
Attackers appear to be using LLMs to generate convincing cover commits alongside the injections.