logo

Frequently Asked Questions About Notepad++ Supply Chain Compromise

ID: 0b332667-b135-57f9-b294-536778ce334e

STIX ID: report--0b332667-b135-57f9-b294-536778ce334e

Feed Name: Tenable Blog

Threat Score
85/100

Date Published: 2026-02-03

Date Updated: 2026-05-01

Author: Satnam Narang

...
...

Threat actors compromised Notepad++'s update distribution infrastructure beginning in June 2025, enabling redirection of update traffic to an attacker-controlled site for targeted espionage. Attribution reports point to the Chinese APT 'Lotus Blossom.' The compromise affected Notepad++ versions up to 8.9 and persisted in stages until December 2, 2025; Notepad++ released version 8.9.1 (adding XMLDSig validation) to remediate the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.