Supply Chain Attack Exploits Notepad++ Update Mechanism to Push Targeted Malware
ID: ef82151b-f2ab-5372-94fe-8bdd2a620ec1
STIX ID: report--ef82151b-f2ab-5372-94fe-8bdd2a620ec1
Feed Name: GBHackers
Notepad++'s update infrastructure was compromised in a prolonged supply-chain campaign (June–Dec 2025) that pushed malicious Notepad++ updates across three distinct infection chains—delivering NSIS installers, Metasploit/Cobalt Strike downloaders, and the Chrysalis espionage backdoor—to individuals and organizations in multiple countries; attackers rotated C2, downloaders, and payloads frequently, maintained access to internal services for months, and were analyzed/blocked by Kaspersky, which provided IOCs and hunting recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
