Notepad++ hijacked by state-sponsored hackers

https://notepad-plus-plus.org/news/hijacked-incident-info-update/

23 points · 5 comments · view on lemmy.world

5 Comments

Wurzelfurz@feddit.org · 5 pts · 208d

He added a link to a deep dive for the backdoor used in the attack.

https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/

artyom@piefed.social · 3 pts · 208d (3 replies)

I'm so confused.

  1. It doesn't say anything about "state-sponsored attackers" outside of the headline? What state? Why?
  2. Why is a Notepad app connecting to any servers or have credentials at all?
voracitude@lemmy.world · 5 pts · 208d
[ removed ]
DemBoSain@midwest.social · 1 pts · 208d (1 reply)

It wasn't specifically notepad++ code, but a custom-written updater. That's why it was connecting to the internet.

village604@adultswim.fan · 2 pts · 208d

I mean, it is n++ code because the updater is part of the code base. They just didn't have the connection to the update server hardened.

This was patched in like December, though.

Calfpupa@lemmy.ml · 3 pts · 208d

It used to be that being a ML (Malicious Linguist) in someones garage was the rage, now we got "Hackers with Chinese characteristics" smh