logo

Supply-Chain Hijacking of Notepad++ Updates via Hosting Provider Compromise (Campaign)

ID: 13e48381-3f41-5715-8675-ea3e637be220

STIX ID: report--13e48381-3f41-5715-8675-ea3e637be220

Feed Name: Wiz Cloud Threat Landscape

Threat Score
88/100

Date Published: 2026-02-02

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Between June and late 2025, threat actors compromised Notepad++'s shared hosting provider and selectively hijacked update traffic to serve malicious update manifests to targeted users. Multiple researchers assess the activity as likely Chinese state-sponsored; attackers lost server access by early September 2025 but retained credentials until early December. The incident was remediated by December 2, 2025, and Notepad++ migrated hosting and strengthened update verification.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.