notepad-plus-plus / notepad-plus-plus/notepad-plus-plus

NPP brand impersonation website serving malware

Open
#18,398 1 comment 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
C++
Stars
29.4k
Forks
5.4k
PR merge metrics
No merged PRs in 30d

Description

notepad-plus-plus [dot] app is a brand impersonation website that copied your site but is serving rotating malware droppers. They also did this to my application, Wisecard 365, and probably other applications.

Infrastructure and methods includes:

  • ficoso [dot] click
  • frapdownload [dot] org
  • EtherHiding
  • unique URLs per victim
  • detection of Node.js to avoid analysis
  • file downloads larger than many scanners allow

While the malicious websites are good clones, the downloads they server don't resemble the real apps at all: different filenames, different contents.

You might want to start by reporting notepad-plus-plus [dot] app and ficoso [dot] click for abuse to:

  • Cloudflare
  • registrar
  • Google Safe Browsing

You could also monitor for brand impersonation like this and other ways.

Some references

This issue is just an FYI: feel free to close this ticket whenever you like.


I've also seen dozens of organizations on GitHub impersonating my app, plus easily 100 other organizations impersonating other apps, and my guess is there are/have been thousands. These all seem to be AI-generated variations created by the same person/group. GitHub doesn't seem to want to find them, and GH makes it difficult for me to report them by rate limiting reports to something like four reports. GH has taken weeks to take them down, too.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No repository file, test, or entry point is identified. Start by reviewing the reported URLs and abuse details, then determine whether the project has an established security-reporting or brand-abuse process; done would require a maintainer decision on appropriate action rather than a repository change.

Written by the indexing model from the issue text.

Assessment

Tech stack
node.js
Domain
security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
15/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.