zlacker

[return to "Notepad++ hijacked by state-sponsored actors"]
1. edb_12+Xc[view] [source] 2026-02-02 04:18:23
>>myster+(OP)
So, let me get this straight. If I've been lazy, postponed updates and I'm still on 8.5.8 (Oct 2023) - it turns out I'm actually...safer?

Anyway, I hope the author can be a bit more specific about what actually has happened to those unlucky enough to have received these malicious updates. And perhaps a tool to e.g. do a checksum of all Notepad++ files, and compare them to the ones of a verified clean install of the user's installed version, would be a start? Though I would assume these malicious updates would be clever enough to rather have dropped and executed additional files, rather than doing something with the Notepad++ binaries themselves.

And I agree with another comment here. With all those spelling mistakes that notification kind of reads like it could have been written by a state-sponsored actor. Not to be (too) paranoid here, but can we be sure that this is the actual author, and that the new version isn't the malicious one?

◧◩
2. hinkle+kd[view] [source] 2026-02-02 04:23:11
>>edb_12+Xc
This reminds me of college, when some of my professors were still sorting out their curriculum and would give us homework assignments with bugs in it.

I complained many times that they were enabling my innate procrastination by proving over and over again that starting the homework early meant you would get screwed. Every time I'd wait until the people in the forum started sounding optimistic before even looking at the problem statement.

I still think I'd like to have a web of trust system where I let my friends try out software updates first before I do, and my relatives let me try them out before they do.

◧◩◪
3. skeled+sb1[view] [source] 2026-02-02 13:58:45
>>hinkle+kd
> let my friends try out software updates first before I do

And who do they let try the software before they do? And so on... Where does it ended?

◧◩◪◨
4. hinkle+gw3[view] [source] 2026-02-03 01:30:14
>>skeled+sb1
There's a few months every year when I'm feeling brave or crazy. We could take turns.

The thing is that most supply chain attacks are going to hit you when you are least prepared to deal with them, because that's exactly how they get you. When you're distracted.

Upgrades are deep work, but the commands to start them feel like shallow work.

[go to top]