[a / b / c / d / e / f / g / gif / h / hr / k / m / o / p / r / s / t / u / v / vg / vm / vmg / vr / vrpg / vst / w / wg] [i / ic] [r9k / s4s / vip] [cm / hm / lgbt / y] [3 / aco / adv / an / bant / biz / cgl / ck / co / diy / fa / fit / gd / hc / his / int / jp / lit / mlp / mu / n / news / out / po / pol / pw / qst / sci / soc / sp / tg / toy / trv / tv / vp / vt / wsg / wsr / x / xs] [Settings] [Search] [Mobile] [Home]
Board
Settings Mobile Home
/g/ - Technology


Thread archived.
You cannot reply anymore.


[Advertise on 4chan]


File: 1761009498994919.png (201 KB, 1156x924)
201 KB
201 KB PNG
Notepad++ hijacked by the Chinese!
https://notepad-plus-plus.org/news/hijacked-incident-info-update/
>>
>updoots are le bad
>>
>>108037988
>get the fauci ouchie edition
>china le bad, save the yoghurts edition
>rusia le bad, save the cukraine edition
>but casually, for some reason, not a single mention of the one country committing an actual genocide
Notepad++ has been hijacked by state sponsored actors for years.
>>
>>108037985
>>
>>108038037
>the one country committing an actual genocide
Sudan?
>>
>>108037988
Why updates / manifests are not signed with developer key?
>>
>>108038236
usa
>>
Damn, that'd suck if I still used Windows.
>>
>>108038281
He couldn't make his updater secure, he was too busy writing his blog because Putin or something.
>>
File: 1770042563735.jpg (268 KB, 1280x755)
268 KB
268 KB JPG
>>108037988
>independaent
>acotor

Why is anyone still using software from this illiterate buffoon?
>>
File: wrong-side.jpg (207 KB, 1280x720)
207 KB
207 KB JPG
opposing software updooot, install and consoooom paradigms comes to be a proper side of "war".

those blank statements may be used to trick retards, a form of GPL-tard engagement, if not proven otherwise. i never saw some "beggar for Ukraine" showed paychecks to confirm his/her support. why is this considered a normal behavior? if you support something, show real-deal reports, paychecks, not this info-fluff.
>>
File: 1769436014839831.png (57 KB, 1268x1152)
57 KB
57 KB PNG
the dude who collects the money is not even in ukraine
>>
you all seem offended by his political incorrectness
>>
File: 1741739791159995.png (335 KB, 659x670)
335 KB
335 KB PNG
>>
File: 1754954344885357.png (15 KB, 690x173)
15 KB
15 KB PNG
>>108038037
>The incident began from June 2025.
>Version v8.7.8: We are with Ukraine - 2025-03-08
>Version v8.X.X: We are with Ukraine
>Version v8.8.1: We are with Ukraine - 2025-05-05
>Version v8.8.2: No political crap - 2025-06-30
so, not only he's an obnoxious piece of shit shoveling politics into software, but he's also a scary cat that cucked out as soon as he got chinked
>>
>>108041515
cry about it HIVan
>>
>>108038037
>the one country committing an actual genocide
South Africa?
>>
>>108038037
>closed with no comment
>>
>>108037988
was ninite safe? which download method was compromised?
>>
>>108038037
>not a single mention of the one country committing an actual genocide
He mentions China regularly.
>>
>some people updating software
lol retards
>>
This means that my passwords stored in my browser have been stolen right ?
>>
>>108043013
ye
>>
File: hLZb1PRl.gif (1.34 MB, 280x263)
1.34 MB
1.34 MB GIF
>>108043146
Thanks. That is good to know.
>>
>>108042142
>which download method was compromised?
The built-in updater.
>>
>>108043699 (cont.)
Which- mind you; you shouldn't have enabled to begin with when it was obvious that the original installer wasn't signed with a valid code-signing certificate.
If they can't sign the original installer, what would make you think they can sign the updates?

It's a MitM waiting to happen. You'd have to be a fucking lunatic to use its auto-updater.
(Well-- or a normie.)
>>
>>108038037
>not a single mention of the one country committing an actual genocide
I wish Israel wiped all mudsiimes off the face of earth, literally nothing of absolutely of any value would be lost whatsoever.
>>
File: O11-606022507.jpg (370 KB, 1920x1372)
370 KB
370 KB JPG
>>108043715
wheres the proof that the author didnt just distributed infected binary himself and then composed an AI story because some user nooooticed a strange behavior?

> many security experts said
> bla bla bla
>>
>>108037988
Jokes on them, I never update that shit, I'm still using some version from 2022.
>>
Okay but how do I even check if I'm infected with Xirus?
>>
>>108043782
the proof is:

> GLORY TO UKRAINE! FREE TIBET!
> ah, okay okay, youre clean

that is the state of complete retardation
>>
>>108037988
I'm using version 8.5.4 from 2023, am I fine?
>>
>>108038037
>the one country committing an actual genocide
You mean Turkey?
>>
>>108043817
check the hash in powershell. can also look in your scheduled tasks to see if theres anything strange in there
Get-FileHash "C:\Program Files\Notepad++\notepad++.exe" -Algorithm SHA256
>>
File: 1770004105016082.jpg (68 KB, 836x705)
68 KB
68 KB JPG
I'm updooting notepad++ through winget. Am I fine?
>>
File: firefox_pOibBJWLqO.png (48 KB, 604x1197)
48 KB
48 KB PNG
haven't updated it in years
>go check the new versions
really nigga?
>>
>>108044960
yea WinGet, Chocolatey, and manual zip installs all seem to be unaffected. think its only because of a hijacked WinGUP or GUP.exe in the updater folder of a normal install
>>
>>108037988
>Since June
Starting hwat day?
>>
>>108043802
>>108044912
Lmao this is why Windows is shit. People never updating their software. Why don't you continue to play MW2 multiplayer lol.

Ironically, in a week Microsoft will update the Windows Defender malware database with these new files and we'll actually get a good picture of how many people are infected.
>>
File: 1767460096776047.png (1.47 MB, 1024x1024)
1.47 MB
1.47 MB PNG
>>108038037
serious question, why do turdies shill for this failed state so much?
>>
>>108037988
>leftist frenchfuck gets cucked
I should feel bad about this?
>>
File: 1758453088280941.jpg (250 KB, 1170x1308)
250 KB
250 KB JPG
>>108043731
You’re not slick Jew. Stop trying to pivot the narrative and treating the rest of the world as le goyim
>>
>>108045267
Because shit works pajeet.
>>
>>108037988
>literally never updated my notepad++
feels good man
time to mig to vim
>>
>>108045786
Use the minimal portable version. It doesn't even have an installer. At this point I wouldn't trust the updater at all. Also get 8.2 if you're anew user. For some reason he's been bloating it over the years. 8.6.9 and newer is more than double the size for absolutely no reason.
>>
File: codered.jpg (30 KB, 398x291)
30 KB
30 KB JPG
>>108037988
>hijacked by the Chinese!
>>
There’s no evidence it was hacked. They can’t say what the “malicious” code is or where it came from. Everything is given in vague terms
>>
>>108045917
>denial
>>
File: LEARN_TO_CODE_DRAW.png (125 KB, 355x330)
125 KB
125 KB PNG
>>108045267
>Why don't you continue to play MW2 multiplayer lol.
>>>/vm/2144355
>>
>>108037988
i heckin luv updates! i update every software the second it's out btw
>>
Nobody I know seems to care
>>
>>108037988
all of us that used winget to update are safe
winget downloads the latest installer from github and it installs on top of your already existing installation
seems like the people that use the update function in notepad++ are the ones affected
>>
File: 1759643036598318.png (18 KB, 405x538)
18 KB
18 KB PNG
>>108037988
updooters lose again
>>
>>108041278
2bh, fuck China after this doubly.
Now I do hate them.
>>
>>108042161
But not Israel?
>>
>>108044960
I might just build from src 2bh. I don't trust the installers now.
>>
>>108041278
wow oh no
some milquetoast opinion held by everyone outside the mainland chinks, how could this be?
>>
>>108041278
Good catch. Most ppl think they hacked it for intelligence value lmao
>>
>>108048381
No, only China gets sovereignty. Anyone else claiming is a threat to Chines sovereignty.
Oh wait, that's Palestine and Israel.
>>
>>108037988
awesome I don't auto-update anything for this reason.
>>108038034
yes. the update mechanisms in most software are the least checked parts of their code.
>>
>>108041515
keeeeeek this is what happened. he got pwned and pissed himself at the possibility of future pwnings once he dipped his toe in the sociopolitical water.
Glad this shit made me swap to sublime.
>>
>>108045972
You can’t claim something happened while offering no evidence that it happened
>>
File: 1759188785492893.gif (85 KB, 638x578)
85 KB
85 KB GIF
I'm on notepad3
>>
>>108037988
Still using 8.7
>>
so what are you supposed to do if you updated in this window but aren't located in asia who was supposedly the target
>>
>>108048879
>https://notepad-plus-plus.org/news/hijacked-incident-info-update/
you donate to Ukraine!
>>
So what was actually in the compromised executables that some people unknowingly downloaded? Did no one ever analyze them yet, or why am I not seeing an information on this?
>>
File: file.png (7 KB, 257x56)
7 KB
7 KB PNG
I don't think I ever consciously disabled updates, but for some reason it never prompted me to update either.
>>
>>108049165
its analysed here:
https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/
>>
What's a good alternative to baizuopad? The announcements on the website and the developers BlueSky rants concern me now that I have learned of them.
>>
>>108038236
Israel. There, I said that, now pray for me.
>>
File: 1747235110203717.gif (54 KB, 498x498)
54 KB
54 KB GIF
>>108049286
Sending thoughts and prayers.
>>
didnt this happen several years ago as well?
>>
>>108049510
good memory
tho that was about external malicious websites that got SEOed above their own result
>>
>>108049173
If you run the installer and choose custom installation, you can choose to skip install on the auto-updater component altogether. Iirc it's also skipped if you choose minimal installation. That's probably what you did.
>>
So what's stopping linux distros repositories from getting hacked the same way?
Does the signing key autism actually pays off?
>>
>>108049152

donate to Ukraine.. who represent Ukraine in there? >>108040906

where can i look at reciets and reports of those crowdfunded money? which military equipment was bought and which military units recieved it?
>>
>>108052574

DonKong HoMon and ChingChong DingDong collect money for Taiwan liberation front..
>>
i downloaded 8.8.5 am i fugged? been having random screen flashes sometimes
>>
>>108052288
>Does the signing key autism actually pays off?
pretty much
>>
>>108037988
Anybody who doesn't hit the official website to manually download the update is a fucking retard.



[Advertise on 4chan]

Delete Post: [File Only] Style:
[Disable Mobile View / Use Desktop Site]

[Enable Mobile View / Use Mobile Site]

All trademarks and copyrights on this page are owned by their respective parties. Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.