Hackers abuse Notepad++ plugins to stealthily install malware
Reported exploitedNotepad++UAC-0099WinRAROur summary
Researchers have identified a new cyberattack method where threat actors disguise malware as Notepad++ plugins to silently install malicious tools on victims' systems. The campaign, attributed to UAC-0099, involves delivering a ZIP file containing a legitimate version of Notepad++ alongside a harmful plugin called NppExport.dll. This plugin, known as LunchPoke, establishes persistence by creating scheduled tasks and downloading additional payloads like BurnyBear and MatchBoil V2. The attack leverages a reported vulnerability (CVE-2025-56383), though the Notepad++ team disputes its classification as a flaw. Security experts recommend updating Notepad++ to version 8.9.7 and WinRAR to 7.23 to mitigate risks.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.