logo

Nation-state hack exploited hosting infrastructure to hijack Notepad++ updates

ID: efb21cff-8bd7-55f8-a7bc-26b488f814d9

STIX ID: report--efb21cff-8bd7-55f8-a7bc-26b488f814d9

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-02-02

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Notepad++ maintainers reported that nation-state attackers compromised a hosting provider’s infrastructure to selectively intercept and redirect software update traffic to malicious servers, enabling distribution of malicious update manifests; the incident is attributed to a likely Chinese state-sponsored group and spanned roughly June through December 2, 2025. The provider moved affected customers, rotated credentials, and the Notepad++ team hardened the updater to enforce certificate and signature checks for future releases.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.