logo

The Notepad++ supply chain attack — unnoticed execution chains and new IoCs

ID: eca4b18e-53ed-51c3-a230-85b1b3644bcd

STIX ID: report--eca4b18e-53ed-51c3-a230-85b1b3644bcd

Feed Name: Securelist by Kaspersky

Threat Score
85/100

Date Published: 2026-02-03

Date Updated: 2026-04-29

Author: Georgy Kucherin, Anton Kargin

...
...

This report details a targeted Notepad++ supply-chain attack (June–December 2025) in which attackers compromised the update infrastructure to push malicious NSIS installers that executed three distinct infection chains delivering Metasploit downloaders, Cobalt Strike Beacons, and the Chrysalis backdoor to dozens of targeted machines (including government and financial organizations); the document includes timelines, technical analysis of payloads and execution techniques (DLL sideloading, exploit-based execution, encrypted shellcode), and a comprehensive set of IoCs and hunting guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.