A Trojan Source attack hides malicious logic in plain sight by using Unicode bidirectional override characters. The code looks correct to a human reviewer but compiles differently.
How the trick works
Text is stored in logical order: the bytes are read left-to-right by the compiler. But the visual renderer follows Unicode bidirectional rules. A character like U+202E Right-to-Left Override can force part of the line to display in reverse order while the compiler still reads the original bytes.
Why it matters for code review
A reviewer might see:
if (isAdmin) { /* safe logic */ }
while the compiler sees:
if (isAdmin) { /* evil logic */ }
The difference is invisible unless you inspect the raw bytes.
What this tool flags
The scanner marks every bidirectional control character with a high-severity finding and shows the surrounding context. It does not block your build, but it gives you a concrete reason to inspect the line manually.
Not all BiDi is malicious
Right-to-left text is essential for Arabic, Hebrew, Persian, and other languages. The risk appears when BiDi controls show up unexpectedly inside code, URLs, or identifiers. That is what the scanner is designed to catch.