Live data from Hacker News

Notepad++ hijacked by state-sponsored actors

notepad-plus-plus.org

161–170 of 560 posts

Re: Notepad++ hijacked by state-sponsored actors

#161
post #56

Earlier quoted context omitted.

It’s a false sense of security, more or less. If an application wants to talk to a C2 they don’t have to make a connection at all, just proxy a connection through something already allowed, or tunnel through DNS. Those juicy cryptocurrency keys? Pop Safari with them in the URL and they’re sent to the malicious actor instantly. If you’re owned Little Snitch does nothing at all for you except give you the impression th…

I find it difficult to believe that there is levels of cooperation between different companies that would allow this to work. Source. I work for a company for longer than the internet has been alive.

You have worked for the same company for >55 years? That's wild. Can you share the industry?

Re: Notepad++ hijacked by state-sponsored actors

#162

why does this read like it was written by a state-sponsored actor

The thought crossed my mind as well. Lots of typos, plus "old version compromised, use new version ASAP" could also be said to get people on a newly compromised version, right? Though it's probably just that the post author is stressed and rushed the post out. I do wonder if there's a way to verify the post was written by the real dev and that he still has control. Old known GPG sig?

Re: Notepad++ hijacked by state-sponsored actors

#163
post #16

This all fascinating, but in the end: I have notepad++; what should I do?

You’d be protected from this particular exploit if you used a package manager rather than the updater, though of course you’d still be vulnerable to the installer binary itself getting compromised.

Wonder how many packages in community package repos are compromised. Surely "Hubbleexplorer" can be trusted to provide arch users with a honest, clean version of npp.

Re: Notepad++ hijacked by state-sponsored actors

#164

Earlier quoted context omitted.

If you think large companies are somehow immune to this, you’re gonna have a bad time.

It's not a matter of "immune" - larger organizations generally have more resources to allocate to things like this. That doesn't mean they get it right 100% of the time, but they are at least able to try, while small teams or volunteer projects often simply don't have the hours to spend on things like this.

lol larger organizations don’t spend money on this, they add some useless ‘secops’ tools to their CI and call it a day. They are certainly not doing things like reproducible builds, lol half of them don’t deploy signature verification.

Re: Notepad++ hijacked by state-sponsored actors

#166
post #61

Earlier quoted context omitted.

I don't know why that comment is being interpreted as a request for alternatives. They are clearly asking if their machine is compromised.

yes, that's my question: am I compromised? What should I do?

Standard answer to a potentially compromised machine is to start with a factory reset machine and add the software and data you need to do your work/use the machine. Do not take executables from the compromised machine and use them any where since they too could be compromised.

There are more steps you can take to ensure greater safety. The above is the minimum a I do for myself and what the minimum IT department and my company executes.

Re: Notepad++ hijacked by state-sponsored actors

#167

Earlier quoted context omitted.

Similar comments also come up in the [now regular] "I don't want to see political articles on HN" threads, and I think the response is similar: Asking for "no politics" is itself a strong political view: One in support/service of whatever the current status quo is. Trying to set oneself apart from (or above) politics is itself political. If you're lucky enough to be one of the fortunate people on earth who are not un…

I partially agree, but as a non-US user of the English speaking internet, the issue is with specifically US politics and social issues being everywhere . It drowns out all attempts at discourse for anything else, and Americans, including people here, seem uniquely incapable of nuance in their thinking when it comes to politics. So, while I fully agree with your stance that banning political discourse is support for t…

This is a good point. What would people think if there was constant political discussion here about, for instance, South Sudan and things happening there now? I'm sure there's bad stuff going on there and it's unfortunately, but if we had constant references to and discussions about the internal politics of South Sudan, I think a lot of people would get annoyed about issues that don't affect them at all in their day-to-day lives, esp. when they're coming here for discussions about technically- and computer-related topics. That must be how it seems for American political discussions.

Re: Notepad++ hijacked by state-sponsored actors

#168

Earlier quoted context omitted.

Yeah, Notepad++ is known for political messaging in their updates. Taiwan, Ukraine, etc.

Probably the real motive.

“ The incident began from June 2025. Multiple independaent security researchers have assessed that the threat acotor is likely a Chinese state-sponsored group, which would explain the highly selective targeting obseved during the campaign.”

How do they know it was a Chinese group or even a state sponsored one?

Re: Notepad++ hijacked by state-sponsored actors

#169

Earlier quoted context omitted.

Similar comments also come up in the [now regular] "I don't want to see political articles on HN" threads, and I think the response is similar: Asking for "no politics" is itself a strong political view: One in support/service of whatever the current status quo is. Trying to set oneself apart from (or above) politics is itself political. If you're lucky enough to be one of the fortunate people on earth who are not un…

I partially agree, but as a non-US user of the English speaking internet, the issue is with specifically US politics and social issues being everywhere . It drowns out all attempts at discourse for anything else, and Americans, including people here, seem uniquely incapable of nuance in their thinking when it comes to politics. So, while I fully agree with your stance that banning political discourse is support for t…

I am an American and I make a very conscious effort to appreciate social and political nuances. And I go out of my way to point out nuances to others who, in my opinion, oversimplify their statements. It could be argued that the expression of stereotyping Americans as lacking nuance, itself lacks nuance. I believe really most people are similar in that we have our biases, differences in context and experiences. We can all try our best to be as nuanced as possible.

Re: Notepad++ hijacked by state-sponsored actors

#170

Probably related to this: https://notepad-plus-plus.org/news/v869-about-taiwan/

Everyone is entitled to their opinions.

My opinion is that open source documentation is like polite dinner conversation: It’s not the proper place to discuss politics.

If an author wishes to use their open source project as a platform to discuss politics, that’s the author’s prerogative. But then, as perhaps in this instance, it could be to the detriment of the project itself.

Post reply on HN