Cambridge researchers have found a new way to encode potentially evil source code. The method exploits subtleties in text-encoding standards such as Unicode to produce source code whose tokens are logically encoded in a different order from the one in which they are displayed. Cambridge University researchers have published working proofs of concept (PoCs) of attacks in the C, C++, C#, JavaScript, Java, Java and Rust, Go and Python programming languages. The attacks jeopardize all source code, posing an immediate threat both to first-party software and of supply-chain compromise across the industry”]
Source: https://threatpost.com/trojan-source-invisible-bugs-source-code/175891/