
Fake Notepad++ Plugin Found Dropping MATCHBOIL.V2 Trojan in Ongoing Attacks
A malicious add-on posing as a legitimate Notepad++ extension is being used to infect developer machines with the MATCHBOIL.V2 remote access trojan, putting website source code, credentials, and hosting environments at r…
Security researchers have uncovered a new campaign delivering the MATCHBOIL.V2 malware through a weaponized installer that mimics a popular Notepad++ plugin. The threat actor, tracked as UAC-0099, has been using the lightweight code editor’s plugin ecosystem to target developers, system administrators, and IT staff—precisely the people who hold the keys to web servers, CMS installations, and cloud dashboards.
MATCHBOIL.V2 is a full-featured remote access trojan (RAT) capable of keystroke logging, credential harvesting, file exfiltration, and establishing persistent backdoors. Once a developer unwittingly loads the rogue plugin, the attacker can silently capture FTP passwords, database connection strings, SSH keys, and WordPress admin credentials. From there, compromising live websites becomes trivial—whether to inject skimmers, deface pages, or turn the host into a spam relay.
For website owners and hosting customers, the lesson is stark: supply-chain attacks that begin on a developer’s local machine can quickly cascade into your public site. The fake plugin was reportedly distributed via direct messages and shady download pages, exploiting the fact that Notepad++ users often overlook verifying the authenticity of third-party extensions. Even if your production server is fully patched, a single trojanized dev workstation can siphon every secret needed to wreak havoc.
To guard against such threats, teams should restrict plugin installations to official repositories, verify digital signatures where available, and run endpoint detection that flags unusual process behavior. Moreover, hosting platforms that provide server-side malware scanning, Web Application Firewall rules, and isolated staging environments add a crucial second layer.
AEU Hosting addresses this risk by offering managed WordPress hosting that includes continuous file integrity monitoring, automatic malware removal, and user-role hardening—ensuring that even if a developer’s local environment is compromised, the damage to your live site is contained and swiftly neutralized.