I was alerted to a recently disclosed Notepad++ vulnerability, CVE-2026-57233, and was told to upgrade. However, the official download page looks unusual because the latest installers have politically themed names, including "Slava Ukraini" and "Tiananmen Massacre Commemoration." Since the project previously experienced a security incident, I'm wondering whether the current downloads and update mechanism are trustworthy or whether it would be safer to wait. Has anyone verified the latest release?
4 Answers
It’s reasonable to hold off if a malware engine flags the installer, especially if you don’t urgently need the update. A single detection can be a false positive, but waiting for the vendor or additional scanners to clarify it is a cautious approach.
The developer is openly activist and uses the release and news pages to make political statements. That can look alarming, but the naming appears to be commentary rather than a sign that the installers are fake. Checking the official security notice, download checksums or signatures, and antivirus results is the better way to evaluate the files.
Version 8.9.7 is reported to be fine. The unusual political wording isn’t new behavior from the developer; similar themed names have appeared on the download page for years, so the titles alone don’t indicate that the files were compromised.
The project has published a clarification about the earlier security incident, and the current release is generally considered safe. It’s still sensible to verify the installer’s signature or submit the downloaded file to a multi-engine scanner such as VirusTotal before running it.

One scanner flagged the MSI as Trojan.MSI.Agent.JUV. That may well be a false positive, but I’m inclined to wait until there’s more confirmation.