zlacker

[return to "Notepad++ hijacked by state-sponsored actors"]
1. wglass+zc[view] [source] 2026-02-02 04:13:56
>>myster+(OP)
Can someone help clarify this for me?

Is it correct to say that users would only get the compromised version if they downloaded from the website?

Notepad++ has auto-update feature, is there any indication that updates from the AutoUpdate were compromised?

◧◩
2. jszymb+Bd[view] [source] 2026-02-02 04:26:42
>>wglass+zc
No, it's specifically the updates that were targetted. I'm unsure about the downloads but those too are presumably at risk.

> The attackers specifically targeted Notepad++ domain with the goal of exploiting insufficient update verification controls that existed in older versions of Notepad++.

[go to top]