Nation-state hack exploited hosting infrastructure to hijack Notepad++ updates
ID: efb21cff-8bd7-55f8-a7bc-26b488f814d9
STIX ID: report--efb21cff-8bd7-55f8-a7bc-26b488f814d9
Feed Name: Security Affairs
Notepad++ maintainers reported that nation-state attackers compromised a hosting provider’s infrastructure to selectively intercept and redirect software update traffic to malicious servers, enabling distribution of malicious update manifests; the incident is attributed to a likely Chinese state-sponsored group and spanned roughly June through December 2, 2025. The provider moved affected customers, rotated credentials, and the Notepad++ team hardened the updater to enforce certificate and signature checks for future releases.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
