LunchPoke malware spreads via disguised Notepad++ plugin installation
Source headline: Hackers abuse Notepad++ plugins to stealthily install malware
Intelligence Summary
Ukraine’s CERT reports campaigns that use Notepad++ as a delivery lure. The malicious package includes the legitimate Notepad++ application and a hidden utility named LunchPoke. Attackers present the payload as if it were a Notepad++ plugin to establish persistence while remaining less noticeable. This technique increases the chance of infections because the installer looks routine to users. Users should verify plugin sources and avoid running unexpected archives or installers for Notepad++.
Recommended Action
Review affected assets, schedule urgent remediation, and monitor related indicators.