https://notepad-plus-plus.org/news/v733-fix-cia-hacking-npp-...
https://notepad-plus-plus.org/news/v733-fix-cia-hacking-npp-...
The fix is just an improved signature check, so that Notepad++ detects if that DLL has been tempered with, by the CIA or anyone else, or by a virus. But as Don Ho himself said, it is a rather weak protection, for that specific attack. Notepad++ is free software, the CIA (or any malware author) can make a version with Notepad++ with a backdoor and there is nothing the author can do, it is true for all free software, and most proprietary software too.
But Don Ho being Don Ho, and because it is the CIA, he had to make a rant about it. I don't like his attempts to push his political opinions with Notepad++, but that's his software, his rights.
His opinions are pretty much just ethical stances, so I have no issues.
You could in theory do something similar with literally any Windows application that links a DLL (i.e. virtually all of them).