Community
    • Login

    Chinese compromise began as early as NP++ v8.6.9

    Scheduled Pinned Locked Moved Security
    4 Posts 2 Posters 1.2k Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Cam KroutC Offline
      Cam Krout
      last edited by

      Hi everybody, new to the forums. This was the first place I could think of that would be appropriate for me to share that I discovered a 32-bit build of Notepad++ from July 12th 2024, not 2025, with obvious evidence of Chinese involvement.

      About.png|

      The earliest Notepad++ version I’ve seen reported as compromised v8.8.3. I simply wanted to present my case of compromise as early as v8.6.9.

      PeterJonesP 1 Reply Last reply Reply Quote 0
      • PeterJonesP Online
        PeterJones @Cam Krout
        last edited by

        @Cam-Krout,

        That’s not evidence of Chinese (state-sponsored) involvement or compromise. That’s specifically the intentional link to the v8.6.9 https://notepad-plus-plus.org/news/v869-about-taiwan/ “Support Taiwan’s Independence” (which is what google translate says those characters mean). The the developer is a huge proponent of such (and his statements in the N++ About box and release pages has a history of taunting state-sponsored attacks on Notepad++ and its infrastructure).

        So that’s rather evidence of the reasons behind the attack, not a symptom of the attack.

        Cam KroutC 1 Reply Last reply Reply Quote 2
        • Cam KroutC Offline
          Cam Krout @PeterJones
          last edited by

          @PeterJones said in Chinese compromise began as early as NP++ v8.6.9:

          @Cam-Krout,

          That’s not evidence of Chinese (state-sponsored) involvement or compromise. That’s specifically the intentional link to the v8.6.9 https://notepad-plus-plus.org/news/v869-about-taiwan/ “Support Taiwan’s Independence” (which is what google translate says those characters mean). The the developer is a huge proponent of such (and his statements in the N++ About box and release pages has a history of taunting state-sponsored attacks on Notepad++ and its infrastructure).

          So that’s rather evidence of the reasons behind the attack, not a symptom of the attack.

          Oh my, I stand corrected. Would have freaked me out less had it used my locale to determine the language for the hyperlink text (I saw that, plus 32-bit, plus a logo I didn’t recognize, and I panicked!)

          But regardless, I appreciate the heads up.

          1 Reply Last reply Reply Quote 0
          • PeterJonesP Online
            PeterJones
            last edited by

            Future readers: if you want more information for the context of this discussion, See the FAQ, which has the best summary I can make, as of 2026-Feb-04; if new information is available, the FAQ will be updated. ALL followups/discussions must go in Topic: autoupdater and connection to temp.sh. This tangent is LOCKED.

            1 Reply Last reply Reply Quote 0
            • PeterJonesP PeterJones locked this topic on

            Hello! It looks like you're interested in this conversation, but you don't have an account yet.

            Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

            With your input, this post could be even better 💗

            Register Login
            • First post
              Last post
            The Community of users of the Notepad++ text editor.
            Powered by NodeBB | Contributors