Live data from Hacker News

Notepad++ hijacked by state-sponsored actors

notepad-plus-plus.org

351–360 of 560 posts

Re: Notepad++ hijacked by state-sponsored actors

#351

Earlier quoted context omitted.

$700+ at Sectigo for two years Something of Notepad++ size might think about it now

the issue was not the money, but that it was difficult to get a certificate without having some sort of legal entity

Certum.eu has this figured out.

https://support.certum.eu/en/code-signing-required-documents...

https://shop.certum.eu/open-source-code-signing-on-simplysig...

$49 (EU) Gross

Re: Notepad++ hijacked by state-sponsored actors

#352

So, let me get this straight. If I've been lazy, postponed updates and I'm still on 8.5.8 (Oct 2023) - it turns out I'm actually...safer? Anyway, I hope the author can be a bit more specific about what actually has happened to those unlucky enough to have received these malicious updates. And perhaps a tool to e.g. do a checksum of all Notepad++ files, and compare them to the ones of a verified clean install of the u…

>I'm still on 8.5.8 (Oct 2023) - it turns out I'm actually...safer? Notepad++ site says The incident began from June 2025. On their downloads page, 8.8.2 was the first update in June 2025 (the previous update 8.8.1 was released 2025-05-05) So, if your installed version is 8.8.1 or lower, then you should be safe. Assuming that they're right about when the incident began. edit: Notepad++ has published, on Github, SHA25…

Older download links doesn't seem to work!?

Re: Notepad++ hijacked by state-sponsored actors

#353

Earlier quoted context omitted.

You can't take a break from that. I have transgender friends who fear for their life every day. They don't know what is going to happen to their rights or their healthcare. I have diabetic friends who can't work and also fear for their life because losing Medicaid would mean they will stop being able to afford insulin and will die . This is what people mean when they talk about politics being important. It's not just…

[flagged]

[flagged]

Re: Notepad++ hijacked by state-sponsored actors

#354

I’m on version 8.8.8, which says a lot. This time I unfortunately have to move on from Notepad++. Vibes have been negative for a while but out of inertia (and because there weren't obvious alternatives) I never pulled the trigger. Now it's time. The trust is gone. Thanks NP++ for being free and useful for so many years. Can anyone suggest a solid alternative on Windows? I'm fine with Linux and macOS but I have to kee…

> I don't like tooling that increases my exposure to bad state actors

> Can anyone suggest a solid alternative on Windows

What a weird reason to switch. I don't know why you'd believe any other piece of software is somehow more secure against state actors.

Re: Notepad++ hijacked by state-sponsored actors

#355

> With these changes and reinforcements, I believe the situation has been fully resolved. Fingers crossed. I get that this is a difficult situation for a small developer, but ending with this line did not fill me with confidence that the problem is actually resolved and make me trust their software on my system.

That's the most honest assessment you can expect from any small-scale developer. What do you expect them to say or do? Their adversary is presumably a national intelligence agency of a superpower . The odds may be better if you operate the way OpenSSH does: move slow, security first, architect everything to be very difficult to attack. But if you're building a text editor, it's not your mindset, and probably never wi…

> The odds may be better if you operate the way OpenSSH does: move slow, security first, architect everything to be very difficult to attack. But if you're building a text editor, it's not your mindset, and probably never will be.

I mean, if you look at the Notepad++ website this developer seems just as concerned at spamming political messaging all over everything as much as he is with writing the software he's distributing. It's pretty crazy he apparently didn't think to take more basic precautions given he is basically permatrolling Russia and China with his messaging. Big brain moment for him. And meanwhile, after reading that disclosure nonsense none of us even know what's going on - like, should we be formatting machines that were affecting during that timeframe? Was the attack targeted and specific only? Who the fuck knows!

Re: Notepad++ hijacked by state-sponsored actors

#356
Many large companies allow employees to install software from the internet on their work laptops. How do they avoid being regularly hacked this way (presumably NPP is far from being the only one at risk, and presumably the money from theft of corporate secrets attracts skilled and motivated hackers).

Re: Notepad++ hijacked by state-sponsored actors

#357
Well, the update in Notepad++ was the single annoying thing and I made sure I turned it off as the first thing after the install. It was terribly annoying, interrupting my workflow every often so I have no idea how others managed. Why should it decide when to upgrade anyway? It's a notepad! Why should I even bother to upgrade? Everything I need is already there! A piece of software like this one shouldn't be allowed to send out traffic by default anyway, it should be opt-in.

Re: Notepad++ hijacked by state-sponsored actors

#358

Earlier quoted context omitted.

Yes, it is very much atypical. Most hacks happen because admins still haven’t applied a 2 years old patch. I hate updates, but it‘s statistically safer that running an old software version. Try exposing a windows XP to the internet and watch how long it takes before it‘s hacked.

Debatable. "I connected Windows XP to the Internet; it was fine" - https://news.ycombinator.com/item?id=40528117 One comment there points out that XP is old enough for infected attack vectors to have all died out. I dunno.

https://www.tomshardware.com/software/windows/idle-windows-x...

But good we are talking about my point rather than than the example.

Re: Notepad++ hijacked by state-sponsored actors

#359

Well, the update in Notepad++ was the single annoying thing and I made sure I turned it off as the first thing after the install. It was terribly annoying, interrupting my workflow every often so I have no idea how others managed. Why should it decide when to upgrade anyway? It's a notepad! Why should I even bother to upgrade? Everything I need is already there! A piece of software like this one shouldn't be allowed…

You should see the apps on MacOS. Almost every single app that is not installed from Appstore has that shitty update popup, it is driving me nuts.

I think Linux has the best solution for this - good package managers for bases system and Flatpak with Flathub repo for other apps. So you never get stupid popups, and update managers use signed packages and check those signatures before installation.

Re: Notepad++ hijacked by state-sponsored actors

#360

Earlier quoted context omitted.

Vim is Charityware. You can use and copy it as much as you like, but you are encouraged to make a donation for needy children in Uganda. Please see |kcc| below or visit the ICCF web site, available at these URLs: http://iccf-holland.org/ http://www.vim.org/iccf/ http://www.iccf.nl/ You can also sponsor the development of Vim. Vim sponsors can vote for features. See |sponsor|. The money goes to Uganda anyway.

Yet another reason Neovim is the superior choice, I suppose

You can also sponsor the development of Neovim. The money goes to funding developers.

https://neovim.io/sponsors/

Post reply on HN