this post was submitted on 02 Feb 2026
529 points (99.1% liked)

Technology

80916 readers
5084 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
(page 2) 41 comments
sorted by: hot top controversial new old
[–] brucethemoose@lemmy.world 16 points 1 week ago

So what malware got shipped?

[–] Dindonmasker@sh.itjust.works 14 points 1 week ago (2 children)

I would like to know starting from wich version should i be concerned. I haven't updated in a while i think.

[–] MangoCats@feddit.it 12 points 1 week ago (6 children)

The timeline says the attack started in June of 2025 and continued through Dec 2, 2025. If you installed, updated, or silently updated during that period you may have been targeted / compromised.

[–] Snazz@lemmy.world 2 points 1 week ago (1 children)

What was the latest version before June 2025?

[–] pez@piefed.blahaj.zone 12 points 1 week ago (1 children)

Looks like 8.8.1 was May 2025 https://notepad-plus-plus.org/news/v881-we-are-with-ukraine/

8.8.2 was June 2025 and has a warning to ignore "false positives" of malware in the update.... Ouch. https://notepad-plus-plus.org/news/8.8.2-available-in-1-week-without-certificate/

[–] AceBonobo@lemmy.world 3 points 1 week ago (5 children)

You might have version 8.8.1 or lower, however it might have tried to order update got the vulnerable package instead and then remained on the older version. I think even if you have the older version that's not a sign that you weren't compromised.

load more comments (5 replies)
load more comments (5 replies)
[–] Kissaki@feddit.org 5 points 1 week ago

Every version before the previous one.

If you haven't updated you were not vulnerable to the update hijacking.

[–] AmidFuror@fedia.io 9 points 1 week ago (1 children)

There were a lot of typos in the linked announcement.

[–] corsicanguppy@lemmy.ca -3 points 1 week ago

If it was important and true, they would've spell-checked.

[–] paraphrand@lemmy.world 8 points 1 week ago

So that’s what the second plus includes….

load more comments
view more: ‹ prev next ›