Notepad++ Hijacked by State-Sponsored Hackers

https://lemmus.org/post/19851429

Yikes… i guess i am confused though. What data was being sent through this channel? What did they get from people while it happened and why did it take 2 months past them stopping it to finally make a release? I love the app, but this sounds really bad.

The previous release already fixed this, or evaded the issue.

The channel was the update mechanism. Upon Notepad++ checking for updates, they were able to inject their own. So if you updated via the apps own update checker they could have misdirected you into installing something else or something modified.