🔐
Security 📅 2026-07-24 · 09:34 AM IST ⏱ 2 min read

Popular Text Editor Under Attack as Hackers Distribute Malware Through Fake Plugin

Cybercriminals are spreading dangerous malware by disguising it as legitimate Notepad++ extensions.

Attackers Weaponize Trusted Software Ecosystem

Security researchers have uncovered a sophisticated scheme where malicious actors created counterfeit plugins designed to look like legitimate add-ons for Notepad++, a widely-used code editing program. These fake extensions were engineered to secretly install MATCHBOIL.V2, a dangerous piece of malware, onto users' computers. The campaign is being attributed to UAC-0099, a group known for conducting cyberattacks against specific targets.

This attack highlights a growing problem: criminals increasingly exploit the trust users place in popular software and its extension marketplaces. Think of it like someone selling counterfeit car parts at an authorized dealership—users assume they're getting the real thing because they downloaded from what appeared to be a legitimate source.

The Broader Security Emergency

Beyond the Notepad++ threat, the cybersecurity community is dealing with a separate but equally serious crisis affecting Redis, a widely-used database technology. The company released seven emergency security patches on July 23rd after researchers publicly revealed how attackers could break into systems running older versions of Redis (6.2.22, 7.4.9, 8.6.4, and 8.8.0).

These vulnerabilities essentially give attackers a master key to databases—allowing them to execute any command they want on vulnerable systems. According to the technical details, the exploits rely on specific database commands and modules, meaning organizations using default configurations are particularly at risk.

Why You Should Care

What You Can Do

If you're a developer or IT professional, take these immediate actions:

For organizations: audit your systems to identify where Redis and Notepad++ are being used, prioritize patching database systems first, and consider deploying endpoint detection tools that can spot malware even if it gets past initial defenses.

These incidents remind us that convenience and security often work against each other—the easier software is to extend and customize, the more opportunities criminals have to slip in malicious code.

📎 This is original ITVedas reporting. This story was inspired by coverage from source. Visit the source for their original reporting.

Want to understand the technology behind this story? ITVedas has beginner-friendly guides on every IT topic.

Explore IT Chapters →