As cited
Copy frozen at (site build).
threat intel
Hackers abuse Notepad++ plugins to stealthily install malware
Ukraine's CERT discovered attackers distributing a malicious tool disguised as a Notepad++ plugin to achieve persistence on compromised systems. The attacks use legitimate copies of Notepad++ bundled with the LunchPoke utility to deceive users into running malware. This technique exploits the trust users place in well-known applications and their plugin ecosystems.
Why it matters: Development teams and general users relying on Notepad++ face direct risk from trojanized downloads; practitioners should validate application sources and review plugin installations for unauthorized persistence mechanisms.
- Source published
- First seen by Cybersecurity Tracker