I don’t think you’ll need to uninstall. If I’m reading the article correctly, it looks like they plugged the hole in their update process by switching hosting providers to one that’s even more hardened and secure. So requests from the updater should go to the correct place now and not the state-sponsored hacker.
Then in about a month, the next version of notepad++ that is released will also properly validate/verify any downloaded update files from the server.
Kazumara@discuss.tchncs.de 14 hours ago
In the old post from when the update was released a Heise article is linked, that contains indicators of compromise, and in turn links to Kevin Beaumont for the details of his analysis:
lemmy.zip/post/54712916
heise.de/…/Notepad-updater-installed-malware-1110…
doublepulsar.com/small-numbers-of-notepad-users-r…