CVE Tools

Hackers abuse Notepad++ plugins to stealthily install malware

BleepingComputerBy Bill Toulas

Reported exploitedNotepad++UAC-0099WinRAR

Our summary

Researchers have identified a new cyberattack method where threat actors disguise malware as Notepad++ plugins to silently install malicious tools on victims' systems. The campaign, attributed to UAC-0099, involves delivering a ZIP file containing a legitimate version of Notepad++ alongside a harmful plugin called NppExport.dll. This plugin, known as LunchPoke, establishes persistence by creating scheduled tasks and downloading additional payloads like BurnyBear and MatchBoil V2. The attack leverages a reported vulnerability (CVE-2025-56383), though the Notepad++ team disputes its classification as a flaw. Security experts recommend updating Notepad++ to version 8.9.7 and WinRAR to 7.23 to mitigate risks.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store