pez

joined 4 months ago
[–] pez@piefed.blahaj.zone 1 points 1 day ago* (last edited 1 day ago)

I mean IOCs that you can scan for in an environment to see if a machine has been compromised using this vulnerability. Something that tells you if you need to do additional remediation on a machine or just update notepad++ and move on.

Edit: Found some! This is the type of info I was thinking of when I used IOCs

https://securelist.com/notepad-supply-chain-attack/118708/

[–] pez@piefed.blahaj.zone 1 points 2 days ago (4 children)

Fair point. I was assuming the malicious payload would come along with an update on order to hide, but it's also possible that the malicious payload was delivered without any update to notepad++.

I've not seen any IOCs published have you?

[–] pez@piefed.blahaj.zone 11 points 3 days ago (6 children)

Looks like 8.8.1 was May 2025 https://notepad-plus-plus.org/news/v881-we-are-with-ukraine/

8.8.2 was June 2025 and has a warning to ignore "false positives" of malware in the update.... Ouch. https://notepad-plus-plus.org/news/8.8.2-available-in-1-week-without-certificate/