For educational purposes only, samples of stealer builders including screenshots.
-
Updated
Aug 1, 2026
For educational purposes only, samples of stealer builders including screenshots.
Closing the localization gap in open source: evidence on how Indic and other under-served locales get reviewed upstream, plus i18n tooling — including i18n-security-lint, a CI scanner for defects in translated strings.
Detect and remove invisible Unicode security hazards. Trojan Source detection, CI checks, and safe RTL handling.
Scan code for invisible bidirectional Unicode characters (Trojan Source attack prevention, CVE-2021-42574)
Research-only AI watermark & provenance robustness toolkit: local reverse proxy (OpenAI/Anthropic/Gemini) + CLI stripping C2PA/EXIF/XMP, zero-width & homoglyph Unicode, KGW text watermarks, DWT/Tree-Ring image stego, AudioSeal, PDF/DOCX/PPTX/XLSX metadata, and Trojan Source (CVE-2021-42574) code scanning.
Catches hidden and invisible-unicode instructions smuggled into AI coding-agent config and skill files. Zero-config CI check.
a modular offensive security framework designed for executing Unicode-based attacks, like those seen in the "GlassWorm" compromises
Reveal & remove invisible, dangerous & confusable characters in your text — zero-width spaces, BOMs, bidi (Trojan Source), homoglyphs, smart quotes. 100% local. Web app + library + CLI.
Desktop scanner for hidden marks and threats in Python code — invisible Unicode, steganography, homoglyphs, secrets and obfuscated code. PyQt6, RU/EN.
Detect, decode and strip invisible/dangerous Unicode (ASCII smuggling, zero-width, bidi Trojan Source, homoglyphs) in LLM text — zero-dep CLI + library.
AI code security scanner MCP server — detects invisible Unicode, Trojan Source, homoglyphs, Glassworm steganography, rules file backdoors, and dependency attacks in AI-generated code. Static analysis + CodeBERT deep learning. Runs locally.
Including XwormV5.6T1, Quasar RAT, njRAT, CraxsRat-v6.8-7.4, RevengeRAT SOURCES.
A security scanner designed to detect invisible Unicode vulnerabilities, BiDi overrides, and homoglyph attacks in source code to prevent Trojan Source exploits.
A linter for the documents your AI agents read. Catches invisible Unicode, hidden HTML-comment injections, prompt overrides, leaked secrets, and OOB-host markdown image exfil.
Before you run AI-generated or downloaded code: a local-first Windows scanner that flags hidden Unicode payloads, auto-run scripts, and malicious AI-agent configs — with a 🔴/🟡/🟢 verdict. No install, nothing leaves your PC.
Reveal invisible-Unicode, bidi (Trojan Source) & homoglyph characters hiding in any pasted text: bookmarklet + npm lib + CLI + static page. General-purpose (email/PR/code review + AI prompts).
Find the ink you can't see. Inspects and cleans invisible Unicode, homoglyphs, and container metadata — deciding per occurrence whether a codepoint is a hidden mark or real content. Zero dependencies.
Pre-commit hook to detect and fix non-ASCII Unicode characters (smart quotes, invisible chars, Trojan Source attacks)
Deterministic offline scanner for repositories and package artifacts, detecting prompt injection, refusal bait, Trojan Source, obfuscation, and supply-chain anti-analysis before AI code review.
Reveal and safely remove invisible Unicode, hidden watermarks, and AI typography from pasted text. Runs in your browser or as a zero-dependency CLI.
Add a description, image, and links to the trojan-source topic page so that developers can more easily learn about it.
To associate your repository with the trojan-source topic, visit your repo's landing page and select "manage topics."