▲ 528 ▼ Notepad++ Hijacked by State-Sponsored Hackers (notepad-plus-plus.org) submitted 6 months ago by Beep@lemmus.org to c/technology@lemmy.world 91 comments fedilink hide all child comments
[–] Snazz@lemmy.world 2 points 6 months ago (1 child) What was the latest version before June 2025? permalink fedilink source parent hideshow 2 child comments replies: [–] pez@piefed.blahaj.zone 12 points 6 months ago (1 child) Looks like 8.8.1 was May 2025 https://notepad-plus-plus.org/news/v881-we-are-with-ukraine/ 8.8.2 was June 2025 and has a warning to ignore "false positives" of malware in the update.... Ouch. https://notepad-plus-plus.org/news/8.8.2-available-in-1-week-without-certificate/ permalink fedilink source parent hideshow 2 child comments replies: [–] AceBonobo@lemmy.world 3 points 6 months ago (1 child) You might have version 8.8.1 or lower, however it might have tried to order update got the vulnerable package instead and then remained on the older version. I think even if you have the older version that's not a sign that you weren't compromised. permalink fedilink source parent hideshow 2 child comments replies: [–] pez@piefed.blahaj.zone 1 point 6 months ago (2 children) Fair point. I was assuming the malicious payload would come along with an update on order to hide, but it's also possible that the malicious payload was delivered without any update to notepad++. I've not seen any IOCs published have you? permalink fedilink source parent hideshow 4 child comments replies: [–] floofloof@lemmy.ca 1 point 6 months ago* (1 child) There's some IOC information here: https://securelist.com/notepad-supply-chain-attack/118708/ And here: https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/ permalink fedilink source parent hideshow 2 child comments replies: [–] pez@piefed.blahaj.zone 2 points 6 months ago Thanks! permalink fedilink source parent [–] AceBonobo@lemmy.world 1 point 6 months ago (1 child) I'm not sure what you mean. The article states there were remote hands on keyboard noticed in multiple companies. That's how the vulnerability was discovered. permalink fedilink source parent hideshow 2 child comments replies: [–] pez@piefed.blahaj.zone 1 point 6 months ago* (last edited 6 months ago) I mean IOCs that you can scan for in an environment to see if a machine has been compromised using this vulnerability. Something that tells you if you need to do additional remediation on a machine or just update notepad++ and move on. Edit: Found some! This is the type of info I was thinking of when I used IOCs https://securelist.com/notepad-supply-chain-attack/118708/ permalink fedilink source parent
[–] pez@piefed.blahaj.zone 12 points 6 months ago (1 child) Looks like 8.8.1 was May 2025 https://notepad-plus-plus.org/news/v881-we-are-with-ukraine/ 8.8.2 was June 2025 and has a warning to ignore "false positives" of malware in the update.... Ouch. https://notepad-plus-plus.org/news/8.8.2-available-in-1-week-without-certificate/ permalink fedilink source parent hideshow 2 child comments replies: [–] AceBonobo@lemmy.world 3 points 6 months ago (1 child) You might have version 8.8.1 or lower, however it might have tried to order update got the vulnerable package instead and then remained on the older version. I think even if you have the older version that's not a sign that you weren't compromised. permalink fedilink source parent hideshow 2 child comments replies: [–] pez@piefed.blahaj.zone 1 point 6 months ago (2 children) Fair point. I was assuming the malicious payload would come along with an update on order to hide, but it's also possible that the malicious payload was delivered without any update to notepad++. I've not seen any IOCs published have you? permalink fedilink source parent hideshow 4 child comments replies: [–] floofloof@lemmy.ca 1 point 6 months ago* (1 child) There's some IOC information here: https://securelist.com/notepad-supply-chain-attack/118708/ And here: https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/ permalink fedilink source parent hideshow 2 child comments replies: [–] pez@piefed.blahaj.zone 2 points 6 months ago Thanks! permalink fedilink source parent [–] AceBonobo@lemmy.world 1 point 6 months ago (1 child) I'm not sure what you mean. The article states there were remote hands on keyboard noticed in multiple companies. That's how the vulnerability was discovered. permalink fedilink source parent hideshow 2 child comments replies: [–] pez@piefed.blahaj.zone 1 point 6 months ago* (last edited 6 months ago) I mean IOCs that you can scan for in an environment to see if a machine has been compromised using this vulnerability. Something that tells you if you need to do additional remediation on a machine or just update notepad++ and move on. Edit: Found some! This is the type of info I was thinking of when I used IOCs https://securelist.com/notepad-supply-chain-attack/118708/ permalink fedilink source parent
[–] AceBonobo@lemmy.world 3 points 6 months ago (1 child) You might have version 8.8.1 or lower, however it might have tried to order update got the vulnerable package instead and then remained on the older version. I think even if you have the older version that's not a sign that you weren't compromised. permalink fedilink source parent hideshow 2 child comments replies: [–] pez@piefed.blahaj.zone 1 point 6 months ago (2 children) Fair point. I was assuming the malicious payload would come along with an update on order to hide, but it's also possible that the malicious payload was delivered without any update to notepad++. I've not seen any IOCs published have you? permalink fedilink source parent hideshow 4 child comments replies: [–] floofloof@lemmy.ca 1 point 6 months ago* (1 child) There's some IOC information here: https://securelist.com/notepad-supply-chain-attack/118708/ And here: https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/ permalink fedilink source parent hideshow 2 child comments replies: [–] pez@piefed.blahaj.zone 2 points 6 months ago Thanks! permalink fedilink source parent [–] AceBonobo@lemmy.world 1 point 6 months ago (1 child) I'm not sure what you mean. The article states there were remote hands on keyboard noticed in multiple companies. That's how the vulnerability was discovered. permalink fedilink source parent hideshow 2 child comments replies: [–] pez@piefed.blahaj.zone 1 point 6 months ago* (last edited 6 months ago) I mean IOCs that you can scan for in an environment to see if a machine has been compromised using this vulnerability. Something that tells you if you need to do additional remediation on a machine or just update notepad++ and move on. Edit: Found some! This is the type of info I was thinking of when I used IOCs https://securelist.com/notepad-supply-chain-attack/118708/ permalink fedilink source parent
[–] pez@piefed.blahaj.zone 1 point 6 months ago (2 children) Fair point. I was assuming the malicious payload would come along with an update on order to hide, but it's also possible that the malicious payload was delivered without any update to notepad++. I've not seen any IOCs published have you? permalink fedilink source parent hideshow 4 child comments replies: [–] floofloof@lemmy.ca 1 point 6 months ago* (1 child) There's some IOC information here: https://securelist.com/notepad-supply-chain-attack/118708/ And here: https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/ permalink fedilink source parent hideshow 2 child comments replies: [–] pez@piefed.blahaj.zone 2 points 6 months ago Thanks! permalink fedilink source parent [–] AceBonobo@lemmy.world 1 point 6 months ago (1 child) I'm not sure what you mean. The article states there were remote hands on keyboard noticed in multiple companies. That's how the vulnerability was discovered. permalink fedilink source parent hideshow 2 child comments replies: [–] pez@piefed.blahaj.zone 1 point 6 months ago* (last edited 6 months ago) I mean IOCs that you can scan for in an environment to see if a machine has been compromised using this vulnerability. Something that tells you if you need to do additional remediation on a machine or just update notepad++ and move on. Edit: Found some! This is the type of info I was thinking of when I used IOCs https://securelist.com/notepad-supply-chain-attack/118708/ permalink fedilink source parent
[–] floofloof@lemmy.ca 1 point 6 months ago* (1 child) There's some IOC information here: https://securelist.com/notepad-supply-chain-attack/118708/ And here: https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/ permalink fedilink source parent hideshow 2 child comments replies: [–] pez@piefed.blahaj.zone 2 points 6 months ago Thanks! permalink fedilink source parent
[–] AceBonobo@lemmy.world 1 point 6 months ago (1 child) I'm not sure what you mean. The article states there were remote hands on keyboard noticed in multiple companies. That's how the vulnerability was discovered. permalink fedilink source parent hideshow 2 child comments replies: [–] pez@piefed.blahaj.zone 1 point 6 months ago* (last edited 6 months ago) I mean IOCs that you can scan for in an environment to see if a machine has been compromised using this vulnerability. Something that tells you if you need to do additional remediation on a machine or just update notepad++ and move on. Edit: Found some! This is the type of info I was thinking of when I used IOCs https://securelist.com/notepad-supply-chain-attack/118708/ permalink fedilink source parent
[–] pez@piefed.blahaj.zone 1 point 6 months ago* (last edited 6 months ago) I mean IOCs that you can scan for in an environment to see if a machine has been compromised using this vulnerability. Something that tells you if you need to do additional remediation on a machine or just update notepad++ and move on. Edit: Found some! This is the type of info I was thinking of when I used IOCs https://securelist.com/notepad-supply-chain-attack/118708/ permalink fedilink source parent