“Ukraine’s CERT has uncovered attacks distributing an archive containing the legitimate Notepad++ application and a malicious utility called LunchPoke disguised as a plugin to establish persistence.”

The Notepad++ binary in the archive is the real one. The persistence rides along as a plugin, which is exactly how plugin systems are supposed to work. Ukraine’s CERT ties the cluster to UAC-0099, which has fed initial access to Sandworm before. Every editor with an extension directory has this same hole and none of them are going to close it.