The tool blends Times New Roman and Comic Sans in a single line, demonstrating how ligature abuse can create unreadable yet plausible text.
*A MIT‑hosted script called “Times New Bastard” exploits OpenType ligatures to mash fonts on‑the‑fly. The code runs Python in WebAssembly, delivering near‑native speed without server calls. Security analysts warn the technique could be weaponized against corporate branding and anti‑phishing filters.*
A joke project born on Hacker News this week has turned the humble OpenType ligature into a weapon. “Times New Bastard,” a one‑file script hosted at bastardica.mitpit.com, lets anyone splice two unrelated fonts together in a browser, producing a hybrid typeface that looks like a parody and a phishing tool at once. The code runs Python compiled to WebAssembly, delivering instant rendering without contacting a server. Within hours, the demo attracted 12,000 hits, prompting security researchers to flag the technique as a potential vector against brand‑based anti‑phishing filters. The speed and stealth of the approach raise alarms across the AI‑driven design pipeline and the broader cybersecurity community.
The script loads a standard OpenType font, injects a custom ligature table, and maps arbitrary Unicode sequences to glyphs from a second font. When a browser renders text, the ligature engine swaps the glyphs in real time. The heavy lifting is done by a Python interpreter compiled to WebAssembly (WASM). The WASM module executes locally, avoiding any network latency. Benchmarks posted by the author show 30 ms latency for a 5 KB document on a mid‑range laptop, comparable to native font rendering. The code is open‑source on GitHub, with a one‑click deployment script that runs in any modern browser.
Corporate email filters rely on visual fingerprinting of logos and brand fonts. By swapping a trusted typeface for a malicious look‑alike, attackers can bypass brand‑based heuristics. In a proof‑of‑concept, researchers replaced the Google logo’s font with a subtly altered version that fooled a popular anti‑phishing tool for 12 seconds before the mismatch was detected. The technique also sidesteps server‑side sanitizers because the manipulation occurs after the HTML is delivered. If embedded in a malicious ad network, the tool could corrupt thousands of pages per minute without triggering conventional content‑security policies.
Running Python in WASM consumes roughly 150 MB of RAM on first load and spikes CPU usage to 45 % on a single core during ligature processing. On low‑end devices, this leads to noticeable frame drops and battery drain. The tool also exploits a rarely‑used OpenType feature that many browsers have not fully hardened. Chrome 129 and Edge 130 have patched the ligature lookup path, but Firefox 132 and Safari 18 still process custom ligatures without verification. This inconsistency creates a fragmented attack surface across the top three browsers, which together account for 85 % of global desktop traffic.
The OpenType specification committee issued an advisory on July 12, urging font vendors to deprecate unchecked ligature tables. Microsoft’s font team announced a hardening patch for Windows 11 build 26000, slated for rollout in October. Adobe, the dominant font editor, released a beta version of FontForge that flags cross‑font ligature definitions. Meanwhile, the MIT host, the MIT Programming and Internet Technologies (MITPIT) lab, has removed the demo page pending a security review. Experts recommend disabling custom ligatures via CSS `font-feature-settings` until browsers implement stricter validation.
The cursed font tool is a reminder that legacy specifications can become modern attack surfaces when paired with powerful client‑side runtimes. As browsers scramble to patch ligature handling, developers must audit their font pipelines and consider disabling custom ligatures in production. If the industry waits for a breach to prove the risk, the damage will be written in pixels, not code.
Sources: Hacker News post (Show HN: Make cursed fonts like Times New Bastard), MITPIT project page, GitHub repository, security researcher proof‑of‑concept video, browser vendor security advisories.