For educational purposes only, samples of stealer builders including screenshots.
-
Updated
Aug 1, 2026
For educational purposes only, samples of stealer builders including screenshots.
Closing the localization gap in open source: evidence on how Indic and other under-served locales get reviewed upstream, plus i18n tooling — including i18n-security-lint, a CI scanner for defects in translated strings.
Analyze your files for hidden characters and watermarks.
Detect and remove invisible Unicode security hazards. Trojan Source detection, CI checks, and safe RTL handling.
Scan code for invisible bidirectional Unicode characters (Trojan Source attack prevention, CVE-2021-42574)
Research-only AI watermark & provenance robustness toolkit: local reverse proxy (OpenAI/Anthropic/Gemini) + CLI stripping C2PA/EXIF/XMP, zero-width & homoglyph Unicode, KGW text watermarks, DWT/Tree-Ring image stego, AudioSeal, PDF/DOCX/PPTX/XLSX metadata, and Trojan Source (CVE-2021-42574) code scanning.
Catches hidden and invisible-unicode instructions smuggled into AI coding-agent config and skill files. Zero-config CI check.
Desktop scanner for hidden marks and threats in Python code — invisible Unicode, steganography, homoglyphs, secrets and obfuscated code. PyQt6, RU/EN.
Detect, decode and strip invisible/dangerous Unicode (ASCII smuggling, zero-width, bidi Trojan Source, homoglyphs) in LLM text — zero-dep CLI + library.
Reveal & remove invisible, dangerous & confusable characters in your text — zero-width spaces, BOMs, bidi (Trojan Source), homoglyphs, smart quotes. 100% local. Web app + library + CLI.
a modular offensive security framework designed for executing Unicode-based attacks, like those seen in the "GlassWorm" compromises
AI code security scanner MCP server — detects invisible Unicode, Trojan Source, homoglyphs, Glassworm steganography, rules file backdoors, and dependency attacks in AI-generated code. Static analysis + CodeBERT deep learning. Runs locally.
Including XwormV5.6T1, Quasar RAT, njRAT, CraxsRat-v6.8-7.4, RevengeRAT SOURCES.
Find the Unicode that hides meaning — bidi controls, invisibles, homoglyphs, mixed scripts
Before you run AI-generated or downloaded code: a local-first Windows scanner that flags hidden Unicode payloads, auto-run scripts, and malicious AI-agent configs — with a 🔴/🟡/🟢 verdict. No install, nothing leaves your PC.
Find and remove invisible characters, lookalike letters, hidden payloads and C2PA provenance metadata in text, documents and images
Reveal and safely remove invisible Unicode, hidden watermarks, and AI typography from pasted text. Runs in your browser or as a zero-dependency CLI.
A security scanner designed to detect invisible Unicode vulnerabilities, BiDi overrides, and homoglyph attacks in source code to prevent Trojan Source exploits.
Find the ink you can't see. Inspects and cleans invisible Unicode, homoglyphs, and container metadata — deciding per occurrence whether a codepoint is a hidden mark or real content. Zero dependencies.
A linter for the documents your AI agents read. Catches invisible Unicode, hidden HTML-comment injections, prompt overrides, leaked secrets, and OOB-host markdown image exfil.
Add a description, image, and links to the trojan-source topic page so that developers can more easily learn about it.
To associate your repository with the trojan-source topic, visit your repo's landing page and select "manage topics."