notepad-plus-plus / notepad-plus-plus/notepad-plus-plus

Question about 2026 Feb security disclosure: Did the Malware Update Notepad++?

Open
#17,478 10 comments 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
C++
Stars
29.4k
Forks
5.4k
PR merge metrics
No merged PRs in 30d

Description

Did the malicious code perform an update of Notepad++? Rapid7, Kaspersky. Based on these articles, the malicious code only provided access to the attacker, but it is not specified whether it actually performed a legitimate Notepad++ update to mask its activity.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reading the linked Rapid7 and Kaspersky reports and compare their descriptions of the Notepad++ supply-chain incident. Determine whether either source documents a legitimate Notepad++ update during the compromise; the issue is complete only when maintainers provide or link to a definitive answer.

Written by the indexing model from the issue text.

Assessment

Tech stack
cpp
Domain
security
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.