11 ms·
Notepad++ supply chain attack breakdown
- troad 8mo agoIt now seems to be best practice to simultaneously keep things updated (to avoid newly discovered vulnerabilities), but also not update them too much (to avoid supply chain attacks). Honestly not sure how I'm meant to action those at the same time.
- deleted 8mo ago[deleted]
- TingPing 8mo agoI feel like supply chain attacks are the much rarer situation than real world exploits but I don’t have numbers.
- krater23 8mo agoSupply chain attacks have impact on more systems, so it's more likely that your system is one of it. Opening a poisoned textfile that contains a exploit that attacks your text editor and fits exactly to your version is a rare event compared to automatically contacting a server to ask for a executable to execute without asking you.
- GauntletWizard 8mo agoUnless there's an announcement of a zero day, update a month after each new release. Keeps you on a recent version while giving security systems and researchers time to detect threats.
- worksonmine 8mo agoDebian stable. If you need something to be on the bleeding edge install it from backports or build from source. But keep most of your system boring and stable. It has worked fine for me for years.
- krater23 8mo agoAs long as you do regulary updates of your debian stable, you are not secured against supply chain attacks.
- worksonmine 8mo agoI don't think you understand Debian. There's a new release every 2 years. A few months before every release there's the so called package freeze on the testing branch. The version the packages are on at that point that's the version they will have for the next stable release. Between releases the only updates are security updates. Do you mean I should worry about the fixed CVEs that are announced and fixed for every other distribution at the same time? Is that the supply-chain attack you're referring to?
- taftster 8mo agoIn the early days, updates quite often made systems less stable, by a demonstrable margin. My dad once turned off all updates on his Windows machine, with the ensuing peril that you can imagine. Sadly, it feels like Microsoft updates lately have trended back towards being unreliable and even user hostile. It's messed up if you update and can't boot your machine afterwards, but here we are. People are going to turn off automatic updates again.
- _carbyau_ 8mo agoI imagine that it depends on the use case. Using notepad++ (or whatever other program) in a manner that deals with internet content a lot - then updating is the thing. Using these tools in a trusted space (local files/network only) : then don't update unless it needs to be different to do what you want. For many people, something in between because new files/network-tech comes and goes from the internet. So, update occasionally...
- gruez 8mo ago>Using notepad++ (or whatever other program) in a manner that deals with internet content a lot - then updating is the thing. Disagree. It's hard to screw up a text editor so much that you have buffer overflows 10 years after it's released, so it's probably safe. It's not impossible, but based on a quick search (though incomplete because google is filled with articles describing this incident) it doesn't look like there were any vulnerabilities that could be exploited by arbitrary input files. The most was some dubious vulnerability around being able to plant plugins.
- _carbyau_ 8mo agoI agree with you regarding particular exploits by arbitrary input files against Notepad++ in particular. I was trying - poorly it seems - to make a more general point regarding exposure to the internet and across "whatever other program" too. Something like 7-zip, VLC, syncthing, whatever other open source tools you may like, and how you use it exposing you to possibility of attack. IE you are interacting with "the wild west of the internet" then the balance of update/not-update shifts more towards update. But if not, then the balance shifts to not-update. But you are correct that either way it depends on the program in particular.
- gruez 8mo agoYou basically need to make a trade-off between 0days and supply chain attacks. Browsers, office suite, media players, archivers, and other programs that are connected to the internet and are handling complex file formats? Update regularly, or at least keep an eye out for CVEs. A text editor, or any other program that doesn't deal with risky data? You're probably fine with auto update turned off
- Marsymars 8mo agoThe easiest way to action as a user seems like it would be to use local package managers that includes something like Dependabot's cooldown config. I'm not aware of any local package managers that do something like this? https://docs.github.com/en/code-security/reference/supply-chain-security/dependabot-options-reference#cooldown- https://docs.github.com/en/code-security/reference/supply-ch...
- ashishb 8mo agoI am running a lot of tools inside sandbox now for exactly this reason. The damage is confined to the directory I'm running that tool in. There is no reason for a tool to implicitly access my mounted cloud drive directory and browser cookies data.
- taftster 8mo agoI almost feel like this should just be the default action for all applications. I don't need them to escape out of a defined root. It's almost like your documents and application are effectively locked together. You have to give permissions for an app to extra data from outside of the sandbox. Linux has this capability, of course. And it seems like MacOS prompts me a lot for "such and such application wants to access this or that". But I think it could be a lot more fine-grained, personally.
- josephg 8mo agoI've been arguing for this for years. There's no reason every random binary should have unfettered, invisible access to everything on my computer as if it were me. iOS and Android both implement these security policies correctly. Why can't desktop operating systems?
- BobbyTables2 8mo agoAnd then there’s dbus… Damn file protection not even enough…
- marky1991 8mo agoMobile platforms are entirely useless to me for exactly this reason, individual islands that don't interact to make anything more generally useful. I would never use any os that worked like that, it's for toys and disposable software only imo.
- josephg 8mo agoMobile platforms are far more secure than desktop computing software. I'd rather do internet banking on my phone than on my computer. You should too. We can make operating systems where the islands can interact. Its just needs to be opt in instead of opt out. A bad Notepad++ update shouldn't be able to invisibly read all of thunderbird's stored emails, or add backdoors to projects I'm working on or cryptolocker my documents. At least not without my say so. I get that permission prompts are annoying. There are some ways to do the UI aspect in a better way - like have the open file dialogue box automatically pass along permissions to the opened file. But these are the minority of cases. Most programs only need to access to their own stuff. Having an OS confirmation for the few applications that need to escape their island would be a much better default. Still allow all the software we use today, but block a great many of these attacks.
- bluenose69 8mo agoThe article starts out by saying that Notepad++ "is a text editor popular among developers". Really?
- maxpert 8mo agoLOL I guess the editors using Notepad++ downvoted you :P
- TingPing 8mo agoLiterally yes: https://survey.stackoverflow.co/2025/ https://survey.stackoverflow.co/2025/
- da_chicken 8mo agoThis might be a better link: https://survey.stackoverflow.co/2025/technology#1-dev-id-es https://survey.stackoverflow.co/2025/technology#1-dev-id-es It's listed as the third most popular IDE after Visual Studio Code and Visual Studio by respondents to Stack Overflow's annual survey. Interestingly, it's higher among professionals than learners. Maybe that's because learners are going to be using some of those newer AI-adjacent editors, or because learners are less likely to be using Windows at all. I'm sure people will leap to the defense of their chosen text editor, like they always do. "Oh, they separated vim and Neovim! Those are basically the same! I can combine those, really, to get a better score!" But I think a better takeaway is that it's incredible that Notepad++, an open source application exclusive to Windows that has had, basically, a single developer over the course of 22 years, has managed to reach such a widespread audience. Especially when Scintilla's other related editors (SciTE, EditPlus) essentially don't rate.
- gruez 8mo ago>Maybe that's because learners are going to be using some of those newer AI-adjacent editors, or because learners are less likely to be using Windows at all. You can use the 2022 (ie. pre-chatgpt) results for control for that. The results are basically the same. https://survey.stackoverflow.co/2022/#most-popular-technologies-new-collab-tools https://survey.stackoverflow.co/2022/#most-popular-technolog...
- Willish42 8mo ago> cmd /c "whoami&&tasklist&&systeminfo&&netstat -ano" > a.txt Naive question, but isn't this relatively safe information to expose for this level of attack? I guess the idea is to find systems vulnerable to 0-day exploits and similar based on this info? Still, that seems like a lot of effort just to get this data.
- thatfunkymunki 8mo agoit's not "just to get that data", it's to confirm level of access, check for potential other exploiters or security software, identify the machine you have access to, identify what the machine has network connectivity to, etc. The attacker then maintains the c2 channel and can then perform their actual objective with the help of the data they have obtained.
- gruez 8mo ago>I guess the idea is to find systems vulnerable to 0-day exploits and similar based on this info? You don't need 0days when you already have RCE on an unsandboxed system.
- porise 8mo agoI guess package managers win in the end. I got two emails from my IT department in the last year telling me to immediately update it.
- Someone1234 8mo agoI'm out of the loop: How did they bypass Notepad++'s digital signatures? I just downloaded it to double-check, and the installer is signed with a valid code-signing certificate.
- tonymet 8mo agoI noticed I had version 8.9 on Dec 28, 2025 and it seems clean according to https://arstechnica.com/security/2026/02/notepad-updater-was-compromised-for-6-months-in-supply-chain-attack/ https://arstechnica.com/security/2026/02/notepad-updater-was... I recommend removing notepad++ and installing via winget which installs the EXE directly without the winGUP updater service. Here's an AI summary explaining who is affected. Affected Versions: All versions of Notepad++ released prior to version 8.8.9 are considered potentially affected if an update was initiated during the compromise window. Compromise Window: Between June 2025 and December 2, 2025. Specific Risk: Users running older versions that utilized the WinGUp update tool were vulnerable to being redirected to malicious servers. These servers delivered trojanized installers containing a custom backdoor dubbed Chrysalis.
- Soerensen 8mo agoThe WinGUp updater compromise is a textbook example of why update mechanisms are such high-value targets. Attackers get code execution on machines that specifically trust the update channel. What's concerning is the 6-month window. Supply chain attacks are difficult to detect because the malicious code runs with full user permissions from a "trusted" source. Most endpoint protection isn't designed to flag software from a legitimate publisher's update infrastructure. For organizations, this argues for staged rollouts and network monitoring for unexpected outbound connections from common applications. For individuals, package managers with cryptographic verification at least add another barrier - though obviously not bulletproof either.
- kijin 8mo agoThe lack of a well-known, well-designed package manager for Windows has always been a problem. Too many programs, including FOSS programs, are downloaded from suspicious-looking websites with tons of ads, and every app updates itself in a different way. The crappy installation and update channels are often tightly integrated with the vendors' monetization strategies, so there's a huge amount of inertia. Microsoft Store could have changed this situation, had it been better designed and better received. Unfortunately, nobody seems to use it unless they have no other choice. WinGet looks much better, but so far it's only for developers and power users.
- ziml77 8mo agoThe Microsoft store would have needed proper vetting and support for normal desktop apps from day 1 for it to actually have been a good option. Also, not requiring the system be set up with an online account would have been helpful for adoption. I can't say it would have guaranteed people would have liked it, just that those were needed for it to have a chance.
- stby 8mo agoI think the Microsoft Store actually did not require the account, which is quite a unique feature across app stores. Whether that is actually relevant on an OS that now forces online accounts in other ways is questionable.
- Erlangen 8mo ago> Notably, the first scan of this URL on the VirusTotal platform occurred in late September, by a user from Taiwan. Could this be the attacker? The scan happened before the hack was first exposed on the forum.
- gruez 8mo agoYou would be a dumbass to do that, because virustotal allows security researchers to see submitted samples/urls. The last thing you want to do is to draw attention to your C&C server.
- wyldberry 8mo agoIt's not uncommon to use VT and other sandbox tools as a proxy indicator for if your attacks have tripped defenders and tooling.
- yodon 8mo agoIs there a "detect infection and clean it up" app from a reputable source yet (beyond the "version 8.8.8 is bad" designator)?
- kijin 8mo agoThe only way to clean up an infected Windows system is to wipe your disk and reinstall the OS. There are so many nooks and crannies where malware can hide, and Windows doesn't enforce any boundaries that can't be crossed with a trivial UAC dialog.
- ziml77 8mo agoI'd say it's more true on Linux that malware can hide anywhere if you allow a sudo prompt (which people have been unfortunately been trained is normal when installing software). Windows enforces driver signing and has a deeper access control system that means a root account doesn't even truly exist. The SYSTEM pseudo-account looks like it should be that, but you can actually set up ACLs that make files untouchable by it. In fact if you check the files in System32, they are only writable by TrustedInstaller. A user's administrative token and SYSTEM have no access those files. But when it comes down to it, I wouldn't trust any system that has had malware on it. At the very least I'd do a complete reinstall. It might even be worth re-flashing the firmware of all components of the system too, but the chances of those also being infected are lower as long as signed firmware is required.
- kijin 8mo agoMalware can't modify files in System32, but it can drop extra files in there no problem. The only way to find and clean them up is a clean install. In Linux, one could write a script that reinstalls all packages, cleans up anything that doesn't belong to an installed package, and asks you about files it's not sure about. It's easy to modify a Linux system, but just as easy to restore it to a known state.
- tonymet 8mo ago
- indigodaddy 8mo agoSo if one were theoretically infected right now, would a Malwarebytes scan indicate as such?
- krackers 8mo agoOP post has an indicators of compromise list, also seen in https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/ https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-... I'm surprised this wasn't linked from the original notepad++ disclosure
- krige 8mo agoIf you can get Malwarebytes to scan anything. It has been such a victim of enshittification, it's not remotely as useful as it were several years ago.
- TurboSkyline 8mo agoIn what ways? I'm still using it the same way I was 10 years ago—on-demand scans of individual files—and it seems to work just as well.
- nightshift1 8mo agoOther source: https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/ https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-...
- ChrisArchitect 8mo agoRelated: Notepad++ hijacked by state-sponsored actors https://news.ycombinator.com/item?id=46851548 https://news.ycombinator.com/item?id=46851548
- iJohnDoe 8mo agoFTA - The original person posting about the unusual behavior was truly helpful. https://community.notepad-plus-plus.org/topic/27212/autoupdater-and-connection-temp-sh https://community.notepad-plus-plus.org/topic/27212/autoupda... Thankfully the responses weren’t outright dismissive, which is usually the case in these situations. It was thought to be a local compromise and nothing to do Notepad++. Good lessons to be learned here. Don’t be quick to dismiss things simply because it doesn’t fit what you think should be happening. That’s the whole point. It doesn’t fit, so investigate why. Most tech support aims to prove the person wrong right out the gate.
- Panzerschrek 8mo agoWhy a simple text editor requires auto-updates at all?
- ddtaylor 8mo agoBecause Windows users don't have basic package management that anyone can use and they probably got tired of idiots getting malware trying to Google random Notepad++ binaries. It's turtles all the way down.
- Panzerschrek 8mo agoThis not answers my question. I just don't see any necessity to update an editor like Notepad++ at all. Such programs are usually stable and there is no need to add new features constantly. Even security vulnerabilities don't matter much, since a text editor isn't that critical piece of software. My Notepad++ installation, for example, is 5 years old and it's fine for me.
- ddtaylor 8mo agoIt probably started with no updates and only a link in the Help menu. Over time they noticed users were getting scammed from Google Ads and other malware delivery methods. As others have mentioned it a program like this should default into a configuration that has no networking capabilities.
- DANmode 8mo ago> Even security vulnerabilities don't matter much, since a text editor isn't that critical piece of software. …that’s not how that decision should be made at all! :]
- benterix 8mo agoI use Notepad++ as a Notepad replacement. I never understood why the network connectivity is enabled by default at all. The first thing I did was to disable it as the constant nagging interrupted my flow (VS Code would do the same thing BTW). I currently have a version from 2020 I'm very happy with. If one day, maybe in 10 or 20 years time, I feel Notepad++ lacks something and I decide to upgrade, I will do it myself, I don't need a handy helper.
- pjmlp 8mo agoNotepad++ is one of my favourite editors, now it is forbidden by IT and checked for on security compliance checks if still installed, thanks to this attack.
- hypeatei 8mo agoYeah, the trust has been burned and the blog post wasn't very reassuring. Safe to say that it will be a long time before it's built back up.
- SideburnsOfDoom 8mo ago> Notepad++ is one of my favourite editors Same, but there are 2 basic key features - tabs, and spell check. There are other nice-to-haves but these are the big ones. Notepad has those features too now. Notepad also has a *#&!$ CoPilot button, but at least you can still turn that off the in the settings.
- pjmlp 8mo agoYou are missing what are actually relevant for me, syntax highlighting, tab completion, projects, and plugins. Notepad has nothing of that.
- SideburnsOfDoom 8mo agoTrue, I should have said "2 basic key features for me" etc. YMMV.
- marxisttemp 8mo agoJust install VS Code
- pjmlp 8mo agoYeah, the only Electron crap that I tolerate.
- 8mo ago
- gethly 8mo agoI just checked, I'm on version 8.8.8. With TinyWall firewall, it has no access to the internet without my explicit say so. This is why constantly trying to be on the bleeding edge of last updates will more likely bite you in the ass than leave your system/program open to attack with some unpatched vulnerability. Look at Windows 11 updates lately. I bet most users would be gladly behind with their updates right now.
- the_harpia_io 8mo ago[flagged]
- 112233 8mo ago> increasingly trust code they haven't personally reviewed while the problems you describe are valid, my personal experience is fully opposite — trust is decreasing. I do not remember anyone worrying about supply chain 15ish years ago — windows was where the viruses lived, and unix people were installing distros, compiling kernel modules and building tarballs without auditing anything.
- the_harpia_io 8mo ago[flagged]
- acdha 8mo ago> developers and users increasingly trust code they haven't personally reviewed. This has been true since we left the era where you typed the program in each time you ran it. Ken Thompson rather famously wrote about this four decades ago: https://www.cs.umass.edu/~emery/classes/cmpsci691st/readings/Sec/Reflections-on-Trusting-Trust.pdf https://www.cs.umass.edu/~emery/classes/cmpsci691st/readings... Sandboxing certainly helps but it’s not a panacea: for example, Notepad++ is exactly the kind of utility people would grant access to edit system files and they would have trusted the updater, too.
- the_harpia_io 8mo ago[flagged]
- acdha 8mo agoYes and LLMs also shift the economics for writing new versus reusing code as well as generating attacks so I think we’ll see some odd variations of old bugs which can’t be widely attacked (not many copies in the world) but might be surprising to someone thinking that problem has been solved (like what happened with Cloudflare’s experimental OAuth library).
- stanfordkid 8mo agoShouldn't public signature of the hash of the exe file from a known key before execution fix this??? What am I missing?
- _zagj 8mo agoThis is the nudge I needed to stop using VSCodium completely. (No offense to its devs, mind you, who seem to much better have their act together.)
- DANmode 8mo agoWhy?
- _zagj 8mo agoVSCode is the most popular IDE right now, making it and its telemetry-free derivative (and their overlapping extension ecosystem) too juicy of a target for a supply chain attack. Over 75% of devs use VSCode, according to the SO survey. And there's also the potential of Codium itself being targeted, despite it currently having a small userbase by comparison, which could easily change as MSFT does to VSCode what it did to Windows. Also, I predict MSFT is going to make it progressively more difficult for the Codium devs to completely strip anti-privacy "features" from VSCode upstream.
- DANmode 8mo agoDefinitely all true! If you don’t need it, I wouldn’t use it. Thanks.
- fjnrnfjfn 8mo agoThe Notepad++ auto updater was quit bad * Enabled by default * No use of verification of the either the update metadata nor the update payload itself Looks like someone wanted to write an auto updater without having the knowledge to do so properly Very sad
- bdavbdav 8mo agoOr the TLS cert of the update server seemingly?
- bdavbdav 8mo agoI get that the installer dropped the app cert, but how did the MITM’d download server pass TLS cert validation? Either they weren’t validating (why???) or they weren’t using HTTPS (why???)