logo

Chinese Hackers Hijack Notepad++ Updates for 6 Months

ID: 878364ca-10c0-5e10-bf51-437a8e072c9f

STIX ID: report--878364ca-10c0-5e10-bf51-437a8e072c9f

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2026-02-02

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

A China-linked advanced persistent threat group compromised a third-party hosting provider to hijack Notepad++'s WinGUp updater from June–December 2025, selectively redirecting targeted users (notably East Asian telecom and financial organizations) to attacker-controlled servers that delivered malicious installers and a custom backdoor; Notepad++ has since migrated hosts and strengthened update verification.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.