The maintainer of Notepad++ has reported that state-sponsored attackers hijacked the utility’s update mechanism to divert update traffic to malicious servers instead.
The attack involves [an] infrastructure-level compromise that allowed malicious actors to intercept and divert update traffic destined for notepad-plus-plus.org, developer Don Ho stated. The compromise occurred at the hosting provider level rather than through weaknesses in Notepad++ code itself.
Ho continued, “The precise mechanism through which this was realized is currently being investigated.”
The development comes a little over a month after Notepad++ released version 8.8.9 to solve an issue that resulted in traffic from WinGUp, the Notepad++ updater, being “occasionally” routed to malicious domains, resulting in the download of poisoned executables read more about Notepad++ Official Update Mechanism Hijacked to Deliver Malware to Select Users
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
