tech
Notepad++ users take note: It's time to check if you're hacked
Suspected China-state hackers used update infrastructure to deliver backdoored version.

TL;DR
- Notepad++'s update infrastructure was compromised for six months, from June to December.
- Suspected China-state hackers used the compromise to deliver backdoored versions of Notepad++ to targeted users.
- The attackers exploited insufficient update verification controls in older versions.
- A never-before-seen payload called Chrysalis was installed by the attackers.
- Three organizations with interests in East Asia reported security incidents resulting in direct hacker control.
- Notepad++ released updates 8.8.8 and later 8.9.1 to address the vulnerabilities.
- Recommendations include blocking notepad-plus-plus.org or gup.exe from internet access for larger organizations.
- Lack of resources may have contributed to the security weaknesses.