ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
HIGH Cybersecurity

LunchPoke malware spreads via disguised Notepad++ plugin installation

Source headline: Hackers abuse Notepad++ plugins to stealthily install malware

Threat level High
Signal strength 75/100
Source confidence 1 source
Published 1 hour ago

Intelligence Summary

Ukraine’s CERT reports campaigns that use Notepad++ as a delivery lure. The malicious package includes the legitimate Notepad++ application and a hidden utility named LunchPoke. Attackers present the payload as if it were a Notepad++ plugin to establish persistence while remaining less noticeable. This technique increases the chance of infections because the installer looks routine to users. Users should verify plugin sources and avoid running unexpected archives or installers for Notepad++.

Recommended Action

Review affected assets, schedule urgent remediation, and monitor related indicators.

Topics

#supply-chain #malware #plugin #persistence #lunchpoke #notepadplusplus
Original reporting BleepingComputer Hackers abuse Notepad++ plugins to stealthily install malware
Open original source