Notepad++ version 8.8.9 was released to fix a security vulnerability in the WinGUp update tool , after researchers and users reported incidents where the updater retrieved malicious executables instead of legitimate update packages.

The first signs of this problem appeared in a Notepad++ community forum topic , where a user reported that the update tool GUP.exe (WinGUp), created an unknown executable file “%Temp%\AutoUpdater.exe” that ran commands to collect device information . According to the user, this malicious executable ran various reconnaissance commands and saved the output to a file named 'a.txt'.
See also: CISA added OSGeo GeoServer vulnerability to KEV Catalog
The autoupdater.exe malware then used the curl.exe command to export the a.txt file to temp[.]sh , a file and text sharing website that has been used in malware campaigns before . Since GUP uses the libcurl library instead of the actual 'curl.exe' command and does not collect this type of information, other Notepad++ users assumed that the user had installed an unofficial, malicious version of Notepad++ or that the autoupdater network traffic had been compromised.
To help address potential network hijacks, Notepad++ developer Don Horeleased version 8.8.8 on November 18th, so updates can only be downloaded from GitHub.
On December 9, version 8.8.9 was released as a more robust fix. This version prevents the installation of updates that are not signed with the developer's code-signing certificate.

“Starting with this release, Notepad++ and WinGUp have been enhanced to verify the signature and certificate of installations downloaded during the update process. If verification fails, the update will be aborted,” states the Notepad 8.8.9 security advisory.
See also: Zero-day Gogs vulnerability used in attacks
Earlier this month, security expert Kevin Beaumont warned that three organizations were reportedly affected by security incidents linked to Notepad++.
The researcher says that all of the organizations he spoke to are linked to East Asia and that the activity seemed highly targeted, with victims reporting hands-on reconnaissance activity after the incidents.
When Notepad++ checks for updates, it connects to https://notepad-plus-plus.org/update/getDownloadUrl.php?version=If a newer version exists, the endpoint will return XML data that provides the download path to the latest version.
Beaumont hypothesized that mechanism automatic update may have been compromised in these incidents, to push malicious updates that provide threat actors with remote access.
“If you can hack and alter that traffic, you can redirect the download to any location that appears by changing the URL in the property,” Beaumont explained.
See also: React2Shell exploit distributes crypto miners

“Because traffic to notepad-plus-plus.org is quite rare, it may be possible to sit inside the ISP chain and redirect to a different download. To do this at any scale requires a lot of resources,” the researcher continued.
However, Beaumont noted that it is not uncommon for attackers to use malicious advertising to distribute malicious versions of Notepad++ that install malware. The Notepad++ security advisory shares the same view, stating that they are still investigating how traffic is affected.
" Investigation is ongoing to determine the exact method of traffic hijacking . Users will be notified once there is concrete evidence regarding the cause ," the security alert states
Notepad++: Protection
The developer states that all Notepad++ users should upgrade to the latest version, 8.8.9. They also noted that since version 8.8.7, all official binaries and installers are signed with a valid certificate, and users who previously installed an older custom root certificate should remove it.
Source: www.bleepingcomputer.com
