tech

Notepad++ users take note: It's time to check if you're hacked

Suspected China-state hackers used update infrastructure to deliver backdoored version.

Notepad++ users take note: It's time to check if you're hacked

TL;DR

  • Notepad++'s update infrastructure was compromised for six months, from June to December.
  • Suspected China-state hackers used the compromise to deliver backdoored versions of Notepad++ to targeted users.
  • The attackers exploited insufficient update verification controls in older versions.
  • A never-before-seen payload called Chrysalis was installed by the attackers.
  • Three organizations with interests in East Asia reported security incidents resulting in direct hacker control.
  • Notepad++ released updates 8.8.8 and later 8.9.1 to address the vulnerabilities.
  • Recommendations include blocking notepad-plus-plus.org or gup.exe from internet access for larger organizations.
  • Lack of resources may have contributed to the security weaknesses.