Comment on Notepad++ Hijacked by State-Sponsored Hackers

<- View Parent
elvith@feddit.org ⁨15⁩ ⁨hours⁩ ago

From my understanding: Basically the attackers could reply to your version check request (usually done automatically) and tell N++ that there were a new version available. If you then approved the update dialogue, N++ would download and execute the binary from the update link that the server sent you. But this didn’t necessarily need to be a real update, it could have been any binary since neither the answer to the update check nor the download link were verified by N++

source
Sort:hotnewtop