

431·
14 days agoJust to be clear, N++ wasn’t compromised, the shared web host running the auto update infrastructure was. They responsibly disclosed it and shared safety steps. I don’t know if it is time to bail on them yet.


Just to be clear, N++ wasn’t compromised, the shared web host running the auto update infrastructure was. They responsibly disclosed it and shared safety steps. I don’t know if it is time to bail on them yet.
Yes, that’s the current consensus. Only the auto-update infrastructure was compromised, and it was a shared hosting compromise.