zlacker

[return to "Notepad++ hijacked by state-sponsored actors"]
1. edb_12+Xc[view] [source] 2026-02-02 04:18:23
>>myster+(OP)
So, let me get this straight. If I've been lazy, postponed updates and I'm still on 8.5.8 (Oct 2023) - it turns out I'm actually...safer?

Anyway, I hope the author can be a bit more specific about what actually has happened to those unlucky enough to have received these malicious updates. And perhaps a tool to e.g. do a checksum of all Notepad++ files, and compare them to the ones of a verified clean install of the user's installed version, would be a start? Though I would assume these malicious updates would be clever enough to rather have dropped and executed additional files, rather than doing something with the Notepad++ binaries themselves.

And I agree with another comment here. With all those spelling mistakes that notification kind of reads like it could have been written by a state-sponsored actor. Not to be (too) paranoid here, but can we be sure that this is the actual author, and that the new version isn't the malicious one?

◧◩
2. beache+vv1[view] [source] 2026-02-02 15:50:19
>>edb_12+Xc
lol, im on 7.3.x for extra safety
[go to top]