CVE-2021-42574, known as Trojan Source, is a source-code review deception issue arising from Unicode bidirectional-algorithm behavior. Bidirectional control sequences can visually reorder source-code characters so that the rendered code reviewed by a human differs from the logical token order processed by a Unicode-accepting compiler or interpreter. An attacker can use these characters in malicious source code or patches to conceal unexpected logic and introduce vulnerabilities without the misleading ordering being readily apparent during review.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (5 hidden).
This repository is a proof-of-concept (PoC) for CVE-2021-42574, which demonstrates the use of Unicode bidirectional control characters to hide malicious code in Solidity smart contracts. The repository contains: - `make_poc.py`: A Python script that generates a Solidity contract (`poc.sol`) with Unicode control characters to visually hide the line `x = 42;` inside what appears to be a comment. This exploits the way some editors and compilers interpret Unicode, potentially allowing attackers to hide malicious logic in plain sight. - `poc.sol`: The generated Solidity contract, which includes the hidden code. - `poc.t.sol`: A test contract for use with the Foundry testing framework, which demonstrates the behavior of the contract and highlights the discrepancy between what is visible in different editors (e.g., Chrome vs. Vim). - `readme.md`: Documentation explaining the exploit, setup instructions, and references to the CVE and related resources. The exploit targets the Solidity compiler and the broader smart contract supply chain, showing how source code can be manipulated to hide logic from reviewers. There are no network endpoints or external IPs; the main fingerprintable endpoint is the `poc.sol` file itself. The PoC is operational as a demonstration but does not include a weaponized payload.
This repository is a proof-of-concept (PoC) exploit for CVE-2021-42574, which demonstrates the use of Unicode bidirectional override characters to obfuscate source code logic in Rust. The main exploit is implemented in 'src/main.rs', where a conditional statement is visually obfuscated using Unicode characters, making it appear as a harmless check while actually performing a different logic. The exploit targets versions of the Rust compiler (rustc) prior to 1.56.1, as indicated in the README.md. The repository includes standard Rust project files and a Dockerfile for building the PoC in a controlled environment. There are no network or external endpoints; the exploit is purely local and demonstrates a source code review evasion technique that could be used to hide malicious logic in codebases.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Trojan Source vulnerability in which Unicode bidirectional control characters can make source code appear different to human reviewers than its logical interpretation by compilers or other tooling. The Rocky Linux advisory addresses the issue through updates to binutils display tools.
Trojan Source is a vulnerability in which Unicode bidirectional control characters can make source code appear visually different from its actual logical interpretation, potentially concealing malicious logic from developers and reviewers.
Trojan Source vulnerability in which Unicode bidirectional control characters can make source code appear differently to human reviewers than to compilers or interpreters, enabling deceptive or hidden code changes. The cited Rocky Linux advisory updates binutils display tools to improve detection and rendering of BiDi Unicode characters.
Referenced as a multiple-products security advisory for unrendered Unicode bidirectional override characters.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.