logo

Notepad++ declares hardened update process 'effectively unexploitable'

ID: 8e8dbaec-da98-5769-9019-f9a4508d3b9e

STIX ID: report--8e8dbaec-da98-5769-9019-f9a4508d3b9e

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2026-02-18

Date Updated: 2026-04-26

Author: Richard Speed

...
...

Notepad++ disclosed that a state-sponsored actor (attributed to the Chinese-linked APT "Lotus Blossom") compromised its update service and selectively redirected update traffic to an attacker-controlled site serving malware disguised as legitimate updates. In response, the project released hardened versions that enforce signed XML and installer verification, removed a vulnerable libcurl.dll dependency, restricted plugin execution to components signed with the updater certificate, removed insecure cURL SSL options, and provided options to disable the auto-updater or deploy MSI without it.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.