Notepad-Plus Fuss: Notepad++ Supply Chain Attack Analysis
ID: 2928b536-4ca0-5b77-97b8-5eee7f77b832
STIX ID: report--2928b536-4ca0-5b77-97b8-5eee7f77b832
Feed Name: LevelBlue SpiderLabs Blog
Threat Score
This report analyzes a targeted supply-chain compromise of Notepad++ where a state-aligned actor hijacked the WinGUp updater to distribute trojanized executables (update.exe/installer_release.exe), detailing payload installation, DLL sideloading, Mark-of-the-Web bypass, timestomping, C2 behavior, CVE-2025-15556, and provided IOCs and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
