Live data from Hacker News

Notepad++ hijacked by state-sponsored actors

notepad-plus-plus.org

41–50 of 560 posts

Re: Notepad++ hijacked by state-sponsored actors

#41

Notably Notepad++ was recently shipping unsigned/self-signed updates, apparently overlapping with the time of this incident, see releases 8.8.2-8.8.6: https://notepad-plus-plus.org/news/

So they just conveniently decided not to sign their releases right around the time they were supposedly "hacked"?

Something doesn't seem right here.

Re: Notepad++ hijacked by state-sponsored actors

#43

I'm extremely wary about any application pushing politics. I subscribe to MacPaw, who makes excellent apps like Setapp, Gemini, and CleanMyMac, all of which I use. At some point, CleanMyMac started putting the Ukranian flag on the app icon and flagging utilities by any Russian developer as untrustworthy (because they are russian), and recommended that I uninstall them. I am not pro russia/anti-ukraine independence by…

if you're going to give in and avoid applications because, like in this case they take a strong stance on Ukraine or Taiwan the hack has literally achieved its purpose. Either silence the author directly or destroy its userbase. Fuck'em and just donate ten bucks to notepad++ , I'd rather my pc breaks then reward this crap

I think I made it clear that I use (and pay for) their applications. I also think I made a sufficiently nuanced comment that doesn't suggest that I've "given in" to anything.

Re: Notepad++ hijacked by state-sponsored actors

#44

Earlier quoted context omitted.

Yeah, Notepad++ is known for political messaging in their updates. Taiwan, Ukraine, etc.

I can't help but feel there must some better venue for such messaging. When I see politics in software updates or documentation, nothing happens because I'm not looking to use the software for political activism. Maybe I tell my adblocker to remove the messaging, and carry on with my task. I can engage with politics in a social context, when political messaging isn't interrupting something else I'm doing; that's a be…

Similar comments also come up in the [now regular] "I don't want to see political articles on HN" threads, and I think the response is similar: Asking for "no politics" is itself a strong political view: One in support/service of whatever the current status quo is. Trying to set oneself apart from (or above) politics is itself political. If you're lucky enough to be one of the fortunate people on earth who are not under attack by political forces or who benefit from status quo politics, I'd encourage you to simply reflect on that good luck and try to ignore the "politics" that others are deeply affected by and care about.

Re: Notepad++ hijacked by state-sponsored actors

#45

Earlier quoted context omitted.

I can't help but feel there must some better venue for such messaging. When I see politics in software updates or documentation, nothing happens because I'm not looking to use the software for political activism. Maybe I tell my adblocker to remove the messaging, and carry on with my task. I can engage with politics in a social context, when political messaging isn't interrupting something else I'm doing; that's a be…

I generally agree with you. But I put up with it since Notepad++ is good software. It is what it is.

[deleted]

Re: Notepad++ hijacked by state-sponsored actors

#47
post #40

Earlier quoted context omitted.

The notepad++ author has publicly come out in favor of Taiwanese independence.

Taiwan is already independent. Surely the normal way to refer to it would be as coming out against assimilation with mainland China?

>Surely the normal way to refer to it would be as coming out against assimilation with mainland China?

I suppose, though that's not really how I tend to see it phrased on socials or in the media.

Re: Notepad++ hijacked by state-sponsored actors

#48

I'm extremely wary about any application pushing politics. I subscribe to MacPaw, who makes excellent apps like Setapp, Gemini, and CleanMyMac, all of which I use. At some point, CleanMyMac started putting the Ukranian flag on the app icon and flagging utilities by any Russian developer as untrustworthy (because they are russian), and recommended that I uninstall them. I am not pro russia/anti-ukraine independence by…

if you're going to give in and avoid applications because, like in this case they take a strong stance on Ukraine or Taiwan the hack has literally achieved its purpose. Either silence the author directly or destroy its userbase. Fuck'em and just donate ten bucks to notepad++ , I'd rather my pc breaks then reward this crap

I support the Ukraine effort as well, but breaking my applications seems like a bridge too far.

Re: Notepad++ hijacked by state-sponsored actors

#49

I'm extremely wary about any application pushing politics. I subscribe to MacPaw, who makes excellent apps like Setapp, Gemini, and CleanMyMac, all of which I use. At some point, CleanMyMac started putting the Ukranian flag on the app icon and flagging utilities by any Russian developer as untrustworthy (because they are russian), and recommended that I uninstall them. I am not pro russia/anti-ukraine independence by…

I hate to say this, but wariness of software developed within Russia has been around for ages, long before the current war.

Since there are a lot of both Ukrainian and Russian software developers, this is personal for a lot of people in the industry.

Re: Notepad++ hijacked by state-sponsored actors

#50
post #36

So uhh... what exactly did the "state-sponsored actors" do? They go on about how their server was compromised, and how the big bad Chinese were definitely behind it, and then claim the "situation has been fully resolved", but there is zero mention of any investigation into what was actually done by the attackers. Why? If I downloaded an installer during the time they were hacked, do I have malware now? The utter lack…

> Even after losing server access, attackers maintained credentials to internal services until December 2, 2025, which allowed them to continue redirecting Notepad++ update traffic to malicious servers. The attackers specifically targeted Notepad++ domain with the goal of exploiting insufficient update verification controls that existed in older versions of Notepad++.
Post reply on HN