An open-source, cross-platform tool called Tirith was released to help prevent command-line “imposter” attacks that abuse Unicode homoglyphs and other terminal-rendering tricks to make malicious URLs and commands appear legitimate. Tirith hooks into common shells (including bash, zsh, fish, and PowerShell) and inspects pasted commands before execution, aiming to stop execution when it detects deceptive URLs or suspicious patterns; the tool is available via GitHub and as an npm package.
Reporting notes that while web browsers have added mitigations for lookalike-domain and mixed-script issues, terminals remain susceptible because they can render Unicode, ANSI escape sequences, and invisible characters in ways that mislead users. Tirith’s stated detection coverage includes homograph/homoglyph domains (including punycode and mixed scripts), terminal injection (e.g., ANSI escapes, bidi overrides, zero-width characters), pipe-to-shell patterns (e.g., curl | bash), dotfile hijacking (e.g., ~/.bashrc, ~/.ssh/authorized_keys), insecure transport (e.g., HTTP-to-shell/TLS disabled), supply-chain risks (e.g., typosquatted repos/untrusted registries), and credential exposure via URL tricks (e.g., userinfo URLs and shorteners).

Get the actors, campaigns, and ATT&CK mapping behind it.
1 event from the most recent confirmed update back to the earliest known activity.
An open-source, cross-platform tool named Tirith was released to detect and block homoglyph URL attacks and other deceptive command-line patterns by inspecting pasted commands before execution. It integrates with zsh, bash, fish, and PowerShell, and also flags risks such as terminal injection, pipe-to-shell patterns, dotfile hijacking, insecure transport, supply-chain issues, and credential exposure.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.