As cited
Copy frozen at (site build).
threat intel
Gifting User Passwords to Adversaries With NPPSPY | Huntress
Security researchers at Huntress identified a method by which threat actors can harvest cleartext passwords using NPPSPY, a Notepad++ plugin framework. The investigation documents how this attack vector enables adversaries to capture user credentials in unencrypted form during normal system activity.
Why it matters: Development and security teams using Notepad++ should audit plugin installations and usage immediately, as this technique allows threat actors to steal passwords at scale from compromised systems.
- Source published
- First seen by Cybersecurity Tracker