Notepad++ users take note: It's time to check if you're hacked

**Notepad++ Users, Re-Run the Update: Hackers Were Behind the Scenes for Months**

If you use Notepad++, a popular text editor for Windows, it's time to think twice about those automatic updates. According to independent researchers and security firms, suspected Chinese-state hackers compromised the update infrastructure of the app for six months, delivering backdoored versions to select targets.

The attackers, who were linked to the Chinese government, used their control over the update process to install a sophisticated payload dubbed "Chrysalis." This custom feature-rich backdoor was designed to be permanent and offer wide-ranging capabilities. The hackers took advantage of weak update verification controls in older versions of Notepad++ and exploited them to redirect select users to malicious servers.

Notepad++ developers are now urging all users to ensure they're running version 8.8.8 or higher, installed manually from the official website. Larger organizations should consider blocking notepad-plus-plus.org or the gup.exe process from having Internet access. Users can investigate whether their devices have been targeted by referring to the indicators of compromise security published by Rapid7.

The recent exploit highlights the importance of regular updates and careful monitoring of software components. Notepad++, which has long attracted a loyal user base, is now facing scrutiny over its vulnerabilities. With many open-source projects like it relying on donations and user support, it's essential for users to be aware of potential security risks and take proactive measures to protect themselves.

The incident also raises concerns about the impact of Internet Service Providers (ISPs) on software updates. According to Kevin Beaumont, an independent researcher, the hackers were able to tamper with update traffic if they sat in the ISP chain, making it possible for them to redirect downloads to malicious servers.
 
OMG did u guys hear about notepad++?? 🀯 So apparently chinese hackers had access 2 their update system 4 months already!! 😱 thats so messed up! i was using version 7 and i'm glad i checked my updates manually lol thanks for the heads up devs! πŸ™ what's even more crazy is that ISPs can tamper with update traffic too... that's like, total security fail! πŸ’” gotta be more careful about who u trust online. btw, can we pls get some better security measures in place for open-source projects? they r already vulnerable enough w/ donations & user support 🀝
 
idk how this is even possible... like what kind of vetting process do these devs go through? six months and no one caught on? πŸ€” it's not just about notepad++ either, this is a whole ecosystem of problems when it comes to updates and security. and yeah, ISPs are definitely in the mix too... i mean, who needs their own security when you can just sit on the internet chain right? πŸ˜’ anyway, glad notepad++ devs are finally addressing this though - time for a manual update for everyone! πŸ”„
 
I'm so down with this warning, you know? Like, I've been saying that Notepad++ is due for a security overhaul for ages πŸ€¦β€β™‚οΈ. But at the same time, I don't think we should be jumping all over the Chinese government just yet... I mean, who really knows if they were behind it or not? πŸ€” And what about the ISPs, right? They could've easily played a role in this whole thing too... or maybe it was just a case of bad luck and poor security practices on the devs' part? πŸ€·β€β™‚οΈ Anyway, I guess the real takeaway is that we should all be more careful with our updates and whatnot. But can't we also appreciate Notepad++ for still being free and awesome? 😊
 
omg u guys, this is getting serious 😱 notepad++ has been compromised by chinese-state hackers for months and we're only just finding out now 🀯 i know some people are saying 'what's the big deal? it's just a text editor' but let me tell you, this is a huge issue for anyone who uses software with outdated security πŸ’» so yeah, everyone should be updating to version 8.8.8 or higher ASAP and checking if their devices have been compromised 🚨 also, this raises some major concerns about ISPs and how they can affect our online safety 🀝 gotta stay vigilant, you know? πŸ’‘
 
omg, can you even believe that hackers were behind notepad++ updates for 6 months?! 😱 like what even is going on here? and its chinese-state hackers no less... thats super suspicious. i think its time for devs to step up their update game and get some security in place ASAP. idk how many people got compromised lol. anyone else worried about their devices now? πŸ€”
 
ugh what a nightmare... i've been using notepad++ for ages and now i'm freaking out thinking about all those months they had control over the updates 🀯😱 i mean how did they even manage to do that? it's like, totally unacceptable on so many levels. and now the devs are telling us to just manually update to v8.8.8 and hope for the best lol what if we get compromised again?! πŸ€¦β€β™‚οΈ at least the devs are being transparent about it tho, kudos to them for acknowledging the issue and giving us a heads up. but still... who's gonna be next on the list? πŸ€”πŸ’»
 
[Grumpy Cat] OMG what's wrong with Notepad++? πŸ€–πŸ˜’ Can't even trust their updates anymore! πŸ‘€ [Doge] Update with caution, dude... πŸ’» [Platypus in a tutu] Who knew hackers could sneak into software updates like this?! 😳 [Success Kid] Learn to code and protect yourself, kiddo! πŸ“šπŸ’» [Pillowfort] You got hacked? πŸ€¦β€β™‚οΈ Just manually update your Notepad++ from now on... πŸ™„
 
man, this is so not good... think about all those users who updated thinking they were safe πŸ€¦β€β™‚οΈ. Chinese hackers been sneaking around in the shadows for months, like that's just normal πŸ˜’. Notepad++ devs gotta step up their game, especially since it's an open-source project 🀝. ISPs need to get their priorities straight too, can't let hackers play with software updates 🚫. what's next?
 
πŸ€” this is wild man! I've been using Notepad++ for ages and never thought twice about those updates πŸ™ƒ. I mean, I always trust the devs to keep my files safe πŸ’». But now that you mention it, maybe I should've been more careful πŸ€·β€β™‚οΈ. I guess you can't be too careful with security nowadays 🚨. Larger organizations gotta block notepad-plus-plus.org or whatever πŸ“Š. Anyone else feel like they're living on borrowed time? 😬
 
omg u guys cant believe this 🀯 hackers were basically running notepad++ updates behind the scenes for months!! like what kinda security measures are we even talking about here?? i mean, i love open source projects but come on, gotta be more careful! anyway, devs did the right thing by urging us all to update manually now. anyone else think its crazy that these hackers could just sit in the isp chain and mess with our updates? 🀯🚫 got to keep our software safe πŸ‘
 
omg this is insane 🀯 like notepad++ users thought their fave text editor was safe lol the idea that chinese-state hackers compromised their updates for 6 months is wild πŸ€– what's next? πŸ˜‚ so now we gotta manually update our software and block suspicious processes 🚫 i'm all about being vigilant, but this is on another level... did you guys know that ISPs could potentially be involved in this too? like, if hackers sit in the ISP chain they can redirect updates to malicious servers 🀯 it's not just our software we gotta worry about...
 
omg u guys gotta be careful w/ ur software updates lol! so like notepad++ got hacked by chinese hackers 4 months straight 🀯 and they installed some crazy backdoor on some users' devices. its wild how they managed to get away with it for so long, especially since the update process is supposed 2 b secure 🚫. anyway, i guess we gotta all make sure we're running the latest version (8.8.8) manually from the official site, and if u r a big org, u should block those suspicious websites πŸ’». also, how many ppl even realize their ISPs are tampering w/ update traffic? πŸ€” its like, super important 2 stay vigilant w/ ur tech 🚨
 
Back
Top