logo

Notepad++ update service hijacked in targeted state-linked attack

ID: ae57753a-679d-5059-a634-2f3562549fce

STIX ID: report--ae57753a-679d-5059-a634-2f3562549fce

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2026-02-02

Date Updated: 2026-04-26

Author: Richard Speed

...
...

Notepad++ confirmed a state‑sponsored compromise of its hosting and update infrastructure in 2025 where attackers redirected selected users to malicious update manifests and distributed malicious updater binaries (e.g., update.exe). The intrusion, likely Chinese state‑sponsored and highly targeted, persisted from June until early December 2025; the project has moved hosting, hardened update verification, and recommends manual installation of the latest secure release.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.