logo

State-Sponsored Actors Hijacked Notepad++ Update Servers to Redirect Users to Malicious Servers

ID: 33dd69be-c78b-5dd0-b63e-1107bbb9accc

STIX ID: report--33dd69be-c78b-5dd0-b63e-1107bbb9accc

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-02-02

Date Updated: 2026-04-21

Author: Guru Baran

...
...

A likely Chinese state-sponsored actor compromised Notepad++'s former shared hosting between June and December 2025, hijacking the getDownloadUrl.php updater endpoint to selectively redirect users to attacker-controlled servers that served malicious installers (including a custom backdoor). The campaign was highly selective and persisted via stolen service credentials after attackers lost direct server access; Notepad++ released v8.8.9 to enforce strict signature and certificate checks and plans XMLDSig for update manifests in a forthcoming release to prevent future tampering.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.