logo

Notepad++ Hijacked: State-Sponsored Actors Poisoned Updates for Months

ID: 9059773a-a445-5694-aaae-ee1ed7516bc0

STIX ID: report--9059773a-a445-5694-aaae-ee1ed7516bc0

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-02-02

Date Updated: 2026-04-23

Author: Ddos

...
...

Notepad++ disclosed a sustained infrastructure-level compromise (June–December 2025) in which attackers who likely belong to a Chinese state-sponsored group hijacked its hosting provider to intercept and redirect update traffic and deliver malicious installers selectively to specific targets; the project migrated hosting and overhauled its WinGup updater (v8.8.9) to add certificate/signature verification and XMLDSig for update manifests, and urges users to update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.