zlacker

[return to "Notepad++ supply chain attack breakdown"]
1. fjnrnf+dH4[view] [source] 2026-02-05 06:29:23
>>natebc+(OP)
The Notepad++ auto updater was quit bad

* Enabled by default * No use of verification of the either the update metadata nor the update payload itself

Looks like someone wanted to write an auto updater without having the knowledge to do so properly

Very sad

◧◩
2. bdavbd+yx7[view] [source] 2026-02-06 00:13:16
>>fjnrnf+dH4
Or the TLS cert of the update server seemingly?
[go to top]