Supply-Chain Hijacking of Notepad++ Updates via Hosting Provider Compromise (Campaign)
ID: 13e48381-3f41-5715-8675-ea3e637be220
STIX ID: report--13e48381-3f41-5715-8675-ea3e637be220
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2026-02-02
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Between June and late 2025, threat actors compromised Notepad++'s shared hosting provider and selectively hijacked update traffic to serve malicious update manifests to targeted users. Multiple researchers assess the activity as likely Chinese state-sponsored; attackers lost server access by early September 2025 but retained credentials until early December. The incident was remediated by December 2, 2025, and Notepad++ migrated hosting and strengthened update verification.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
