Notepad++ update service hijacked in targeted state-linked attack
ID: ae57753a-679d-5059-a634-2f3562549fce
STIX ID: report--ae57753a-679d-5059-a634-2f3562549fce
Feed Name: The Register (Security)
Threat Score
Notepad++ confirmed a state‑sponsored compromise of its hosting and update infrastructure in 2025 where attackers redirected selected users to malicious update manifests and distributed malicious updater binaries (e.g., update.exe). The intrusion, likely Chinese state‑sponsored and highly targeted, persisted from June until early December 2025; the project has moved hosting, hardened update verification, and recommends manual installation of the latest secure release.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
