State-Sponsored Actors Hijacked Notepad++ Update Servers to Redirect Users to Malicious Servers
ID: 33dd69be-c78b-5dd0-b63e-1107bbb9accc
STIX ID: report--33dd69be-c78b-5dd0-b63e-1107bbb9accc
Feed Name: cybersecurityNews.com
A likely Chinese state-sponsored actor compromised Notepad++'s former shared hosting between June and December 2025, hijacking the getDownloadUrl.php updater endpoint to selectively redirect users to attacker-controlled servers that served malicious installers (including a custom backdoor). The campaign was highly selective and persisted via stolen service credentials after attackers lost direct server access; Notepad++ released v8.8.9 to enforce strict signature and certificate checks and plans XMLDSig for update manifests in a forthcoming release to prevent future tampering.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
