logo

Supply Chain Attack Exploits Notepad++ Update Mechanism to Push Targeted Malware

ID: ef82151b-f2ab-5372-94fe-8bdd2a620ec1

STIX ID: report--ef82151b-f2ab-5372-94fe-8bdd2a620ec1

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-02-04

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Notepad++'s update infrastructure was compromised in a prolonged supply-chain campaign (June–Dec 2025) that pushed malicious Notepad++ updates across three distinct infection chains—delivering NSIS installers, Metasploit/Cobalt Strike downloaders, and the Chrysalis espionage backdoor—to individuals and organizations in multiple countries; attackers rotated C2, downloaders, and payloads frequently, maintained access to internal services for months, and were analyzed/blocked by Kaspersky, which provided IOCs and hunting recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.