
Fake Notepad++ Plugin Spreads MATCHBOIL.V2 Backdoor in UAC-0099 Campaign
A malicious plugin for Notepad++ is being used by threat group UAC-0099 to deliver the MATCHBOIL.V2 backdoor, posing risks to developers and their managed websites.
A new campaign attributed to the threat actor group UAC-0099 leverages a fraudulent plugin for the widely used code editor Notepad++ to distribute a backdoor known as MATCHBOIL.V2. The attack highlights how threat actors continue to target developers' tools to compromise systems that are often connected to sensitive web hosting and IT infrastructure.
The malicious plugin mimics a legitimate extension, enticing users to install it from untrusted sources. Once activated, it drops MATCHBOIL.V2, a remote access trojan that can exfiltrate credentials, execute commands, and maintain persistent access to the infected machine. Because Notepad++ is commonly employed by web developers and system administrators, the breach of a single developer’s workstation can cascade into a much wider compromise, including the defacement or backdooring of managed websites.
For website owners and businesses, this incident underscores the risk of supply-chain-style attacks where insecure development environments become entry points into production systems. An attacker with a foothold on a developer’s machine may steal SFTP keys, session tokens, or database passwords, then directly alter hosted content or inject malicious code into a live site.
To mitigate such threats, it’s critical to restrict plugin installations to official repositories, enforce endpoint detection and response (EDR) on developer devices, and apply the principle of least privilege across all infrastructure. For website owners relying on managed platforms, employing a host with server‑side integrity checks and automated malware scanning—like the security‑first approach of AEU Hosting—can help detect unauthorized changes quickly, even if a developer’s local environment is breached.