Chinese Hackers Hijack Notepad++ Updates for 6 Months
ID: 878364ca-10c0-5e10-bf51-437a8e072c9f
STIX ID: report--878364ca-10c0-5e10-bf51-437a8e072c9f
Feed Name: Dark Reading
Threat Score
A China-linked advanced persistent threat group compromised a third-party hosting provider to hijack Notepad++'s WinGUp updater from June–December 2025, selectively redirecting targeted users (notably East Asian telecom and financial organizations) to attacker-controlled servers that delivered malicious installers and a custom backdoor; Notepad++ has since migrated hosts and strengthened update verification.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
