• REDACTED@infosec.pub
    link
    fedilink
    English
    arrow-up
    3
    ·
    edit-2
    14 hours ago

    Correct me if I’m wrong, but initial news about it serving malicious updates were false. You never got anything malicious thru updates, neither was the exe file/installer tampered with. The worst they actually did was redirect you to a fake site when pressing download, where the malicious file was distributed. GitHub and signed versions were never affected. What’s also interesting is that the attacker selectively redirected people, not all of them. I always installed n++ using Ninite, so I’m in the clear.

    The whole thing seems blown out of proportions. The amount of affected people is likely very small.