Thread #108042472 | Image & Video Expansion | Click to Play
HomeIndexCatalogAll ThreadsNew ThreadReply
H
File: file.png (49 KB)
49 KB
49 KB PNG
>if you updated Notepad+++ anytime between now and 2025 you're computer is compromised

How do we cope with this?
+Showing all 250 replies.
>>
some people that develop and publish a text editor in the spare time for you to use for free don't have airtight security processes and post mortems? call the police, unacceptable
>>
IOCs are out now
https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/
>>
>>108042472
by checking the catalog before opening the fifth thread for this shit
>>
>>108042472
Notepad++ folder
last update: 2015-2016.

Another L for the updoooters camp. (anyone got the meme pic?)
>>
>>108042472
one of the things that let them deliver payloads this was microshit's warbird lmao.
>>
>>108042594
geany
>>
>>108042598
quit livin on dreams
>>
>>108042594
>shill me your open sauce alternatives /g/
srsl?
well ok. General editors (hard mode) : vim, emacs, also gvim, neovim
General editors: kate. geany is usually weaker imo. Gedit might be most weak (simple re programming).

Good IDEs and still easy to start using: qtcreator - mainly for C/C++. You can make any program in it, also terminal programs, it reads CMake files too (dont have to actually develop with Qt libs nor use qmake despite the name).
>>
>>108042610
>qtcreator
oh and also - kdevelop.
>>
>>108042598
looks like it came out of windows 98, neat

>>108042610
and what if i autistically utilized notepadPP for everything? kate seems like a strong contender after all the vims

ty anons
>>
>>108042472
I'm so curious how many Linux repo mirrors are secretly compromised. I bet it's MANY.
>>
>>108042594
ed is the standard text editor
>>
>- Notepad++ suspects it is the Chinese government
>- No evidence provided currently demonstrating why they suspect it was the Chinese government
So the schizo hijacked his own software to make a political statement.
>>
>>108042472
Who the fuck still uses Notepad++?
>>
>>108042688
The same people using utorrent. lol
>>
>>108042688
what's a good alternative that's run by competent people
>>
Notepad++ is owned by the US government so you were already compromised from since it began
>>
>>108042570
>anti-update schizos are still trying to brush the april 2025 4chan hack under the rug
>>
>>108042762
VS Code
>>
>>108042801
>>anti-update schizos are still trying to brush the april 2025 4chan hack under the rug
when you run a server - then update the last stable. if possible build from sources
>>
>>108042594
Kate
>>
>>108042901
He said competent people, not jeets and AI
>>
How does someone hijack your server and you don't realize for half a year?
>>
>>108042919
>jeets jeets jeets jeets jeets jeets jeets jeets jeets jeets jeets jeets
I am 100% White European and I'm get tried of this
>>
>>108042941
Stop replying to ragebait bot posts
>>
>>108042940
It was only the update release infrastructure, something you setup once and don't look at often unless someone complains about it.
>>
>>108042472
This is why I block all online functionality in apps that don't really need it. The only thing that should get through your firewall are browsers and OS updates.
>>
>>108042944
There's nothing ragebait about not wanting to use microslop products.
>>
>>108042472
>tfw use Helix I build from source for Windows.
Rust bros... we won.
>>
>>108042472
>haven't updated since 2024
win by doing nothing
>>
>>108042472
Haven't used that shit since like 2011 and I'm on Manjaro since last year.
>>
sublGAWDS...!
>>
>>108042688
Is notepad++ supposed to be obsolete in some manner? Hard mode: don't mention "waah they had update names supporting politics I was told to dislike".
>>
>>108043108
The fact that the dev sees his program as a platform for political bullshit is a security risk by itself because it shows a level of mental instability attached to something that you're installing on your computer.
>>
>>108043129
This. It's like eating a sandwich made by a guy whose face is smeared with shit.
>>
>>108043129
This is only really true when the dev is leftist
>>
>>108042472
I remember that around October last year someone got access to all my accounts. All of them: banks, social media, Steam, emails, etc. Everything except things with 2FA.

I suspected that my PC was infected so I reinstalled Windows. I had absolutely no weird software on that PC, but I did have an updated version of Notepad++ and I still do.
>>
>>108042472
Oh no.
>>
>>108043129
>>108043159
>it's le SECURITY ISSUE because dev supports a sovereign nation that's being invaded
Oh, but I'm sure if the epstein psyop board convinced him to support pootin instead, it would be perfectly fine.
>>
>>108043159
Well if he was conservative he would still be pro-israel so what difference does it even make? This shit just doesn't belong in a god damn text editor.
>>
>>108042684
>muh ukraine
>muh china
>muh rich african and bluesky
holy fuck this guy is obsessed with politics
>>
>>108043177
>Well if he was conservative he would still be pro-israel
Only if he was an amerimutt, in which case that's a separate red flag and you should avoid using american products in general
>>
>>108042598
geany is absolute dogshit, it's unusable if you've used any modern option like vscode. it's clunky to the extreme and missing every feature under the sun
>>
>>108042472
>be retard sperging politically in updates
>people don't care and call me stupid
>idea.jpg
>add malware to my releases for a few months
>say it was ze evil chinese who did it
>say only "select individuals" were targetted so people will keep using my crapware
>profit?
>>
>do a clean install of W10 back in October last year
>download N++ from scoop
>use scoop exclusively to manage my updates, never using the in-built autoupdoot feature from N++
Am I fucked?
I'd rather not halt my work and spend an entire week doing backups/reinstalling my whole system just because this jackass couldn't keep his political opinions to himself.
>>
>it is those DASTARDLY CHINKS because.... uhhhh
>>
File: notepad++.png (24.9 KB)
24.9 KB
24.9 KB PNG
>>108042472
not my problem
>>
>>108042940
It was shared hosting infrastructure and it was actually part of the shared infra that was compromised and was chaining incoming requests meant for Notepad++'s update URL to an attacker-controlled system.

There would've been very little signals for Notepad++'s author to have been able to pick up on.
>>
>>108042472
Why the fuck would you be running an "updater" for a text editor? Is it a reddit thing?
>>
not my problem, only running n++ on the PC at work (lol)
>>
>>108043243
>Am I fucked?
No. It was specifically the self-hosted update infrastructure that was compromised.
>>
>>108042594
Why am alternative to Obsidian? I just recently started using it so genuinely curious.
Notepad++, been a long time user. I rely on its keyboard shortcuts for moving text around, it's column editor, and the many other ways it lets you control text. Also things light marking and highlighting. When I, and probably others, ask for an alternative, it needs to be really damn close.
>>
>>108042570
you need at least 7.3.3 (released 2017-03-08) where he fixed he CIA hack
>>
>>108043243
If you trust the lead dev no people were affected, only bugs (his words).
>>
>>108042472
So is my We are with Ukraine version safe?
>>
>>108042472
>How do we cope with this?
what do you mean we white man? I haven't updated mine since I installed it in 2020.

what idiot sets his software to automatically update?
>>
>>108042472
President Xi, My name is Ken Thompson. I am 82 years old. I live in California. My government has backdoored my compiler, and the NSA is running crypto miners even though RAM is getting more expensive. Please send Chengdu J-20 Multirole Stealth Fighter Aircraft through my Notepad++.
>>
>>108042472
The dev posted several "stand with palestine" messages, i wonder who would want to hack him
>>
>>108043231
Shades of BetterWayElectronics here
Soon he'll lockout the program if he detects you running any Russian made software, or if you have a browser with a tab on 4chan open
>>
Thank god I'm a lazy retard and update shit through winget
>>
>>108042594
Zed is pretty good and is lightweight for the features it offers.

>>108042647
Typing binary code directly onto the drive cells using microscopic probes is easier than using ed.
>>
Installed it dozens of times on customers computers, always using the same installer from 2019 or so and disabling updates
>>
>>108042472
>How do we cope with this?
By not being a wintoddler or an updooter
If you are either uninstall yourself from /g/ immediately and don't come back
>>
>>108043884
See: >>108042801
>>
File: a.jpg (30 KB)
30 KB
30 KB JPG
>Windows' notepad has cloud garbage and takes 5-10 seconds to open
>Subilme is abandonware that you also have to pay
>Vs Code takes 500mb of RAM an 10 seconds to open a 30kb .txt file
>Notepad++ is a security risk thanks to the Dev's retardation
is having a free, simple, lightweight text editor with markups too much to ask?
holy shit, the absolute state of fucking windows' text editors
>>
>>108043921
I don't run a million user imageboard on my computer. In fact my computer doesn't have to deal with any adversarial user input at all. You're retarded if you can't see the difference
>>
Cracked out of date sublime text chads win again
>>
>>108043949
>>Windows' notepad has cloud garbage and takes 5-10 seconds to open
Isn't it possible to replace the exe with an older version?
>>
>>108043973
>being this pedantic
Update your software, retard.
>>
>exe last modified in late 2020
I almost updated it last year too because I was having problems with it while trying to edit the lua of a gmod mod.
>>
File: file.png (7.1 KB)
7.1 KB
7.1 KB PNG
>>108044096
Why though? Unironically what's the usecase? What do you actually think is going to happen?
>>
File: file.png (2.9 KB)
2.9 KB
2.9 KB PNG
>>108042472
Did it get updates?
>>
>>108044203
>hurr durr what's the use case of updating software I'm on /g/ technology but don't understand what an update involves
Get your ritualposting retard ass out of here. This is supposed to be a board for people who have a greater grasp on technology than baby boomers who don't know how to set a timer on a VCR.
>>
>>108043167
>>108043263
>>108044261
these. why do people update working software unless there's a bug directly impacting your experience? it's rare I've updated something and been impressed by new functionality, they usually just make shit worse.
>>
>>108042472
Emacs once again demonstrates it's superiority.
>>
>>108042643
There is no group more complacent when it comes to security than linux users.
>>
>>108042594
Kate, the text editor used on the Steam Deck.

What's the matter, you don't trust Valve?
>>
>>108044320
Not sure why you have to seethe so hard about it. All my software works fine, it makes no sense to update until I actually run into a bug or a missing feature. Enjoy your compromised notepad++ though, I bet that new version brought plenty of exciting new features and the update was worth it
>>
>>108044394
What's not trustworthy about an American corporation?
>>
>build time: Dec 8 2025
>>
>>108042911
>still can't reopen unsaved files from last session
trash. Sublime text is infinitely better
>>
File: IMG_5545.gif (98.4 KB)
98.4 KB
98.4 KB GIF
so if I downloaded it in June from the website but never updated it what does that mean? Am I still fucked
>>
>>108042594
notepad++commonsense
>>
>>108042472
I never updated Notepad++ through the update mechanism.
>>
>>108042940
He had a website set up on some hosting provider. The hosting provider got rekt and the attackers allegedly began selectively delivering compromised updates. Now the other problem comes in, namely that older versions of Notepad++ did not verify any signatures or such on the update installer they downloaded, which then means that the targeted users just got rekt.

Making an auto-updater with no signature / validity checks of the downloaded update seems like an extremely bad practice, but as for detecting the actual compromise on the hosting provider, that seems very difficult for the dev to do. If this was actually targeted at whoever the fuck (not specified) then they would have probably not served any compromised shit to the dev himself if he tested it, so he wouldn't find out.

The big question is how the hosting provider got rekt and didn't know it.
>>
File: file.png (84.1 KB)
84.1 KB
84.1 KB PNG
>build time: feb 6 2025
so im safe?
>>
Ok so if I never actually used the built in update mechanism and only ever installed a version off the website and then never upgraded it after am I fine?
>>
you now remember the puush hack
>>
>>108044884
>so if I downloaded it in June from the website but never updated it what does that mean? Am I still fucked
No, if you downloaded any version but never used their dumbass updater you are fine

Why the fuck would I update their software, what could possibly be of interest in the patch notes
>>
>>108043194
Runs fast.
I had to use a Lenovo M73 mini PC from 2014 recently, even VSCODE for basic Python scripts struggled on that thing. Geany was a lifesaver. That shit flew fast.
>>
do i need to make my own fucking text editor wtf is this shit
>>
>>108042684
>>108043179
>>108043108
Didn't use Notepad++ because of the shitty icon/logo, the politics is just a bonus
>>
>use php for your updater
>get pwnd
>>
>>108042594
should be using micro or nano. everything else is either bloatware or tryhard bullshit
>>
>>108042541
I updated it all the time and have none of those IOCs.
Clearly only targets even got served the modified installer. Don't need to worry about it if you're on some random home computer.
>>
>>108042472
So like, this only affects users who've used the updater within the program itself? I had to reinstall it around november but I went and downloaded directly from the website, no clue if I'm fucked or not
>>
>>108045154
>do i need to make my own fucking text editor wtf is this shit
Unironically, and I actually hate AI since I'm in tech and it's making people into fucking idiots, homebrewing your own text editor has never been simpler
>>
>>108042472
Oh come on, I just reinstalled Windows and downloaded a fresh installation of NPP a week or two ago...
>>
>>108042995
How did you do it? My router is an old TP-Link from like 2015 and the firmware was never updated and it is notoriously unreliable so I just used my Huawei modem directly with my SIM card most of the time.
>>
>>108042472
>How do we cope
don't need to "cope", I just never update a fucking text editor
>>
File: lmao.png (9.5 KB)
9.5 KB
9.5 KB PNG
>>108044330
That's nothing babe, check this.
>>
>>108045448
that's pre-cia patch, check version 7.3.3
https://notepad-plus-plus.org/downloads/v7.3.3/
>>
>>108045448
so instead of being compromised by the chinese, you're compromised by the CIA, which is the worse of the two lol
>>
File: lmao.png (69.9 KB)
69.9 KB
69.9 KB PNG
>>108045463
>>108045478
>dude just load this dll and then I can hack you!
every time...
>>
>>108042472
Another reason why I backup old version of shit when I download them. I've used the same version across multiple OS versions for over a decade. Feels comfy.
>>
so the issue with the update.exe?
holysht glad i'm using simplewall, it probably blocked any update attempt
>>
I don't like anything about this I read their terrible typo ridden blogpost and it was all the 3rd party said this said that they fixed this they said that.

Notepad++ is run by retards that don't know shit. It will never be on any of my devices ever again. Open sores garbage strikes again.
>>
>>108042570
>I STAND WITH UPDOOTS
>WE MUST ALWAYS UPDOOT
>>
I updated around Jan 20 without a thought.
Am I fucked?
>>
>>108042472
> you are computer is compromised.
K bud
Anyway, only retards use notepad++ in the last 15 years. Maybe longer.
>>108042610
Don't forget bluefish
>>
>>108043194
We're comparing to Notepad++. Geany is just as capable as that dogshit
>>
never updated, and still never will
and im not changing text editors
you cant hurt me jack
>>
>>108042472
Thankfully I'm running the 7.33 portable version.
>>
>>108045692
you're safe (if the hosting provider isn't lying)

>According to the former hosting provider, the shared hosting server was compromised until September 2, 2025. Even after losing server access, attackers maintained credentials to internal services until December 2, 2025,
>>
>>108042594
Micro? Nano? VI(m)? eMacs?

>Obsidian
It depends on what you're using Obsidian for, really.
>>
What's the best way to check if I'm compromised?
>>
Usecase for notepad?
>>
>>108042472
>I'm safe
time to jump ship. zed or vim? I particularly liked notepad++ keeping unsaved documents on program restart
>>
>>108045763
so I can just keep using the notepad++ version I already have, nothingburger except for updooters?
>>
File: t.jpg (65.9 KB)
65.9 KB
65.9 KB JPG
>>108045818
run a scan using: bitdefender free (it's the best desu, worked on a virus i had long time ago. malwarebytes couldn't find it)
if by any chance it finds something, format

>>108045826
I moved to Kate lol not trusting noepad++ again
>>
>>108045852
yep you're safe
never update
>>
>>108042472
>its another hack involving always updating
>always the dead programs that just work and never need updating
Only Indians would be upset about this.
>>
>>108042472
hey guys theres a new text editor that microsoft built into windows in the latest update, type edit in the cmd
>>
>>108042684
>v8.6.9 -> v8.7
>v8.7.9 -> v8.8
Did it happen to work out that way or do they not know how version numbers work?
>>
>>108045916
smartest american
>>
>>108045916
hes a moron who is constantly shilling for CURRENT THING, what do you think
>>
>>108045958
this site would actually be consistently good if all amerimutts were rangebanned
>>
>>108045406
>Using a TP-stink in 2026
I’m so sorry for you anon.
>>
File: file.png (8.1 KB)
8.1 KB
8.1 KB PNG
>>108042472
how fucked am i right now
>>
>>108046373
Have you ever denied that Taiwan is Chinese property?
>>
I installed during the period, but as far as I can tell you were only exposed if you ever clicked yes to update the software.
>>
>>108046373
Time to learn Mandarin my boy
>>
File: file.png (30.5 KB)
30.5 KB
30.5 KB PNG
>>108046393
>>108046438
i believe that CHINESE TAIPEI is part of CHINA, there is only one CHINA with its capital in BEIJING and its leader as XI JINPING, with CHINESE TAIPEI as a province of CHINA.
>>
>>108042472
ffs i might have, I had an old version I transferred and got a new laptop in that timeframe
>>
>>108045826
Vscodium retains unsaved stuff
>>
>>108042472
What kind of retard willingly installs known malware? There's no reason a fucking text editor has this many "vulnerabilities", all of you fell for it
>>
>>108042594
notepad++ is already open source
just audit the code if you're unsure if it's safe
>>
>>108042643
most distros have package signing
>>
>>108045860
I tried out Bitdefender and that shit installed like 800mb worth of unnecessary bloatware. Holy fuck that shit is cancer
>>
>>108043174
Doesnt the hack prove that its a security issue?
>but muh the other side!!!!!
kys
>>
>>108042472
I don't get it, does this affect the autoupdate feature in the program itself or the one in the server?
>>
>>108042594
doom emacs
>>
>>108046908
>actually falling for the shill
>>
vim chads can't stop winning
>>
>>108046968
Oops quoted the wrong person. Meant for >>108046899
>>
>>108043274
>There would've been very little signals for Notepad++'s author to have been able to pick up on
time for him to start auto running a script that checks the hash of his internal build and the one being hosted
>>
>>108045958
no, he's right
https://semver.org/
>>
>>108046899
>using windows
>>
>>108042472
all of us using winget to update are safe because winget downloads the latest installer from github and install on top of the already existing installation
if you updated using the automatic update from within notepad++ you were a target
what got hacked was the notepad++ updated server not github
the binaries were always on github
>>
>>108043787
winget chads
we won
>>
How many times must updooters suffer before they stop updooting?
>>
>>108042472
>hmmmm that's odd, why is something trying to connect to some chink IP?
>oh well who cares, keep it blocked
adblock solves browsing the internet
a simple firewall (like, say, the aptly named simplewall) solves security
>>
>notepad++ / kate for simple edits
>vs codium for more demanding shit
you don't need more
you don't need obsidian either, it's just markdown so use what you already have
>>
File: file.png (17.6 KB)
17.6 KB
17.6 KB PNG
pic related and a firewall rule to not let your notepad application connect to the internet. there, I fixed it
>>
>>108042594
notepadd++ s already opensource
>>
scanned with defender and eset
got nothing so i guess i'm good
>>
>>108045109
Memory unlocked.
I now remember that puush existed.
>>
>vx-underground
OP
KILL YOURSELF
IN REAL LIFE
>>
>>108045406
>How did you do it?
simplewall
>>
>>108042684
Holy fuck what a schizo.
What text editors/ideas are free from this political and gay bullshit. Why can't they just program apps without the need to be a fucking schizo.
Fuck i hope neovim is free of this shit, it's my goto editor atm.
>>
hello my chink spy, pls no hack
>>
>>108042472
>>if you updated Notepad+++ anytime between now and 2025 you're computer is compromised
>check my Notepad++ version
>Build time : Mar 15 2021
I'm safe.
>>
>>108043787
>>108047572
>winget update -all
>leave to take a shit
>>
File: done.jpg (66.1 KB)
66.1 KB
66.1 KB JPG
Worst part is that I notice it being off after June.

Not that it matters, this machine's been bugged probably since day 1 I am beginning to assume. Never buy second hand.
>>
>>108048282
>leave
>not sitting on a sysadmin bucket
>>>/v/
>>
>>108048454
Sorry I'm a windowschad not some linu- excuse me gnu/linux caveman
>>
>>108043787
The version installed through winget still uses the built-in auto-updater unless you explicitly disabled it.
>>
>>108042541
>>108045277
Check your %temp% folder for the previous installers and compared the SHA256 to the ones on the official github

Strangely enough, I only had the installers for 8.8.7 and 8.8.8, but they both matched the official ones

And I don't have the %appdata%\bluetooth folder either, so I think I'm good.
>>
File: hqdefault.jpg (24.1 KB)
24.1 KB
24.1 KB JPG
>>108042472
>june 2025
so almost certainly mossad trying to get into iranian nuclear sites again cause they used this EXACT same vector (compromised updates) to spread eternalblue and crash iranian centrifuge a few years back
>DURR ITS PROBABLY CHINA
yeah china during the 12 day war you fucking retard
>>
>>108042472
I am considering right now if it is even worth it to continue using it. those updates with political messages may have doomed the software to a life of irrelevancy.
>>
why are there multiple threads on this
>>
>>108042538
Signing releases isn't exactly hard to implement nor "airtight security".
>>
>tfw using a portable version from like 2023
updooters btfo again
also fuck the captcha 3 times choose the 2 star bullshit
fuck you nigger
>>
>>108046908
No, the hack doesn't prove that "I like Ukraine over the apes invading it and support Taiwan as an independent country instead of being psyop'd into thinking winnie the poo is a good leader" is a security concern. By all means, have your ideals shaped by fear like a pussy, be told who to support by the epstein-founded psyop board.
>>
>>108050034
Got no notepad++ installers in temp folder.
Does that mean I never used the auto updater?
I'm on 8.8.8, but I have the memory of an ant so I genuinely can't remember if I updated it or not.
>>
>>108042801
I am pretty sure an opened port in a fucking notepad application I also have firewalled for good measure will be my undoing.
Fucking moron.
>>
>>108042472
>using auto updaters ever
You get what you fuckin' deserve.
>>
>>108042472
LIVING ON THE EDGE
>>
>>108047572
Afaik Winget just downloads the regular Notepad++ installer and executes it with silent and yes-to-all flags, which means it would install with the full default configuration, including installing the auto-updater component, which comes pre-enabled under default initial settings.

You're fucked.
>>
>>108042472
>ctrl+f "scite"
> 0 results
>>
>>108052127
i have never seen that update window
notepad++ doesnt run in the background
it doesnt have any scheduled tasks or service
you are retarded
what was compromised was their update servers which could be used to prompt the user to download the infected binaries
winget downloads the latest installer from github and runs the installer which installs on top of the already existing installation
it isnt a true package manager like the linux ones
i dont even think notepad++ has an auto updater
it automatically checks for updates and prompts the user to download it
>>
>>108050257
I'm trying out of Geany right now, and it seems like a fine alternative
>>
For what it's worth here's a script to scan for IoCs https://github.com/CreamyG31337/chrysalis-ioc-triage

[spoiler]I'm too retarded to know how to properly run this, if someone could tell me step by step instructions because copy pasting onto powershell itself just results in an error[/spoiler]
>>
>>108054358
no idea why that didn't spoiler, goes to show how useless I am...
>>
>>108054358
There's a quick-start guide that tells you exactly what to type into PowerShell, which is a part of Windows and as such installed on your computer already
>>
>>108054358
>>108054578
Sorry, I started writing that before reading all of your post. In the first line you have to replace "" with the URL you posted. To run PowerShell as admin, just type "PowerShell" into the start menu and right-click the icon when it appears. Though I can't vouch for the script itself in anyway, I don't know how those things work so I can't read through it
>>
>>108042472
> uninstalled notepad++ because of the woke ukraine retardation
> /g/ why did you do that anon? there's literally no reason to do that just use the software and ignore the politics!
I am vindicated. My IQ is triple yours.
>>
>>108042472
kek SublimeText wins again
>>
>>108055895
mirin.
how do u like my
i stopped using the internet entirely
>>
Why are you all worried about being compromised by the CCP? Israel and Russia already have your data anyway.
>>
>>108042472
I run stable distribution hardened Linux and use vim I don't care about Notepad shitshit.
Only Windows shitters have to cope with having no text editors besides notepad.
>>
File: file.png (139.6 KB)
139.6 KB
139.6 KB PNG
>>108042684
>>
>>108055952
Why be willfully ignorant?
>>108039757
>>
>>108045185
>>108042688
Don Ho is not happy with me--that's okay, I'll still keep using his garbage.
>>
>>108042472
I'm in the clear
>>
>>108055931
how light is subline?
i just need a light text editor with syntax highlighting to edit files from time to time
>>
File: poop.png (26.5 KB)
26.5 KB
26.5 KB PNG
>>108056293
Here is a portable version 3 build folder size.
>>
>>108056313
any particular reason why you are using 3 instead of 4?
>>
>>108056352
It still works and I downloaded the portable version 9 years ago.
>>
>>108042901
>launching a whole fucking browser to edit a text file
Nadella?
>>
>>108056293
Couple of scratch text tabs and a few small .txt files opened
>>
>>108042472
How do you not have a feature on the updater that checks if the updated files are signed by the proper people?
>>
am I dead?
>>
>>108056770
Just go to the notepad++ site, download the installer and update manually.
>>
>>108042941
Ok so stop advocating white replacement in white countries by jeers, it’s it that complicated
>>
>>108054372
/g/ doesn't have spoilers
>>
>>108042472
archlinux (btw)
>>
>>108043152
Lmfao
>>
>>108043159
Kek suckless software for example is shit, and notepad++ devs are libtards not leftists.
>>
>>108042472
haven't updated it since june 2024 :D
>>
>>108046456
You spelt TAIWAN wrong
>>
>>108042541
>the goys are onto us, quickly what's a convincing name for a Chinese hacker group?
>Lotus Blossom
>>
Notepad++
> only supports windows 7+
> very political comments inside software
> supports ukraine's mission to send innocent men to die for zelensky's wallet

Code::Blocks
> supports XP (and even win95 if you compile for ansi)
> so many plugins and features
> entirely scriptable, like, you can make it do anything or add menu items that'll do something
> russians and ukrainians can both work on it without hateful propaganda getting in the way
>>
I knew postponing all those upgrades was a good idea
>>
>>108054358
This shit doesn't even work, just throws out error messages
>>
>>108057977
Kek
>>
>>108057996
I SWEAR YOU'LL NEVER SEE ANYTHING LIKE THIS EVER AGAIN
>>
>>108042472
Based. Time to update
>>
>>108054358
looks like im all clear?
PS C:\Users\anon\Downloads\chrysalis-ioc-triage-master\chrysalis-ioc-triage-master\scripts> .\Check-ChrysalisIoC.ps1 [*] Checking known paths... [*] Checking mutexes... [*] Checking Run keys... [*] Checking services... ========== Summary ========== No Chrysalis IoCs detected in checked locations. Consider running with -ScanPaths to hash more directories (e.g. -ScanPaths 'C:\Users','C:\ProgramData'). Report saved: C:\Users\anon\Downloads\chrysalis-ioc-triage-master\chrysalis-ioc-triage-master\scripts\..\chrysalis-scan-20260204-121419.json PS C:\Users\anon\Downloads\chrysalis-ioc-triage-master\chrysalis-ioc-triage-master\scripts>
>>
>>108058067
whats the error message? im a certified moron and i got it to run with little trouble
>>
File: blue.gif (24.8 KB)
24.8 KB
24.8 KB GIF
>>108042472
Not my fucking problem. Only retards get automatic updates.
>>108042901
Only a troll or a massive retard would answer like that.
>>
>>108042538
But they do have time to add manifestos on Ukraine, ICE, and trannies.
>>
>>108057996
Probably some jeet or cartel spam.
I would report and delete such emails.
>>
>>108060238
I copied the shit it says under Quick Start and changed the URL bit but it doesn't work
>>
>>108042472
>INCIDENT BEGAN JUNE 2025
When the developer let his certificate provider contract lapse.
>HOSTING INFRASTRUCTURE SAYS SEPTEMBER 2, 2025
Shortly after the developer started signing his own root certificate.
https://notepad-plus-plus.org/downloads/v8.8.3/
>Notepad++ STATES THEY BELIEVE COMPROMISE WAS JUNE THROUGH DECEMBER
The months where the certificate was lapsed and then self-signed, up until another certificate authority took over in December.
https://notepad-plus-plus.org/news/v887-released/

So lets get this straight. The developer lets his security certificates lapse over the matter of a hundred or so dollars a year, after getting nine years free. He then begins signing his own certificates rather than paying his current provider or any other provider. In the update name, he brags about it being self-signed as:
>Download Notepad++ v8.8.3 - Self-signed Certificate: Certified by Code, Not Corporations"
Literally bragging about not having a certificate authority involved. Fine. Maybe you're better at it. Lets see.
Then he gets a new provider and he calls the update "Authenticity Guaranteed"
Then in December he releases two updates:
>vulnerability-fix; and
>security enhancements
Then on February 2nd he's informed for the first time there's a security problem? And that China did it?
This smells fishy, boys.
>>
>>108061814
Correction: he paid for the new certificate authority in October, not December. So the timeline is
>June: notepad++ certificates expire for non-payment
>July: developer self-signs and releases update bragging about not having a certificate authority
>October: developer pays for a certificate authority out of his own pocket and brags about how authenticity is now secured
>December: developer releases a two updates titled: vulnerabilities-fix and 'security enhancements;
>February 2nd 2026, morning: developer made aware of compromise to notepad++ update system from June to December 2025
>February 2nd 2026, afternoon: developer (known to be insane) blames the Chinese government
>>
>>108042472
No issue at all.
>in linux
Kate, Kwrite, gedit, nano, vim, whatever
>in windows
Notepad2, baybee

Also, having auto-updates for programs without user confirmation should be prohibited. We already get enough shit with chrome extensions that start off good, but then get bought out and 2 years later become a botnet.
>>
A text editor has no reason to require any kind of access to the internet.
>but muh updates!
A separate updater program can take care of that.

Hopefully you have proper firewalling set up... Or just use an editor that doesn't fucking use the net.
>>
cock
>>
if i turned off the internal updater and relied on chocolatey upgrades, how likely am i to have been pwned?
>>
File: checksum.png (44.5 KB)
44.5 KB
44.5 KB PNG
>>108062114
update: all the Chocolatey checksums match, it's all good.
>>
File: Untitled.png (80.9 KB)
80.9 KB
80.9 KB PNG
>>108062114
>>108062204
Package repo model of distribution has been vindicated once more. Most software shouldn't have their own mechanisms for software updooting.
>>
>>108048051
hope you like saving starving children in Uganda.
>>
>>108062114
package managers like winget and chocolatey downloaded the latest installer and run it to install on top of your already existing installation
windows doesnt have a "real" package manager like linux distributions because thats not how it works on windows
so as long as you didnt use the notepad++ updater you should be safe
i also always update software with winget so we should be safe
>>
File: file.png (58.9 KB)
58.9 KB
58.9 KB PNG
>>108042762
>>
>>108050938
Certs cost like $300 a year for code signing and require annoying to set up infrastructure. I'm not surprised a lot of open source projects don't bother. It's actually cheaper and easier to do the apple code signing stuff on macOS.
>>
>>108061814
desu, if I was giving away my software for free, the amount of money I would be willing to pay out of my own pocket to deliver it would be $0. Can't blame him.
>>
>>108062808
You can blame him for some things. A better solution might have been
>Hey guys, we lost our certificate sponsor and I can't afford one on my own, so I'm either going to need $400 in donations or we go manual downloads only
I agree nobody should expect him to pay for everything himself. Then again there are probably a dozen or so free ways he could be securely distributing this stuff besides his own special update module.
My main point is that he doesn't seem to be completely honest with himself or with others about how this could have happened.
>>
>>108062038
>Kate, Kwrite, gedit, nano, vim, whatever
None of these fulfill the same role as notepad++. The UX of notepad++ is that you can have it open at all times on the side with many tabs. Almost like a browser without taking gigabytes of RAM.
>>
>>108062866
I believe several of those have tabs...
>>
File: geany.png (4.3 KB)
4.3 KB
4.3 KB PNG
>>108062866
Geany seems to fit the bill for me, but it's clearly made with Linux in mind. Setup on Windows is kind of annoying, like having to create a settings file in AppData\Local\gtk-3.0 to get fucking dark mode
>>
File: npp.jpg (6 KB)
6 KB
6 KB JPG
phew
>>
>>108062866
Kate certainly has tabs.
>>
>>108042684
Ah yes because we all know the chinese and the russians sure do keep to themselves and never hack anyone ever! They are friendly and never do anything nor would they ever do anything in favor of there own government! Please fucking kill yourself.
>>
>>108050034
I cleared my temp folder at some point so I don't have the files anymore. I don't have the bluetooth thing but from what I understand they would be able to execute a cleanup as well.
>>
>>108042472
remember that the faggot behind notepad++ is politicaltard https://archive.is/p2saA
make of that what you will
>>
>>108062999
>>108062878
It's not about tabs, it's about having a very small UI footprint while being interactable through the GUI
>>
>>108042472
Oh fuck off, I just reformatted on January 25th.
>>
>>108062866
>The UX of notepad++ is that you can have it open at all times on the side with many tabs
>>108063163
>It's not about tabs
Of course. Beg my pardon.
>>
i always updated through winget

Reply to Thread #108042472


Supported: JPG, PNG, GIF, WebP, WebM, MP4, MP3 (max 4MB)