logo

Notepad-Plus Fuss: Notepad++ Supply Chain Attack Analysis

ID: 2928b536-4ca0-5b77-97b8-5eee7f77b832

STIX ID: report--2928b536-4ca0-5b77-97b8-5eee7f77b832

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
90/100

Date Published: 2026-02-10

Date Updated: 2026-04-28

Author: King Orande

...
...

This report analyzes a targeted supply-chain compromise of Notepad++ where a state-aligned actor hijacked the WinGUp updater to distribute trojanized executables (update.exe/installer_release.exe), detailing payload installation, DLL sideloading, Mark-of-the-Web bypass, timestomping, C2 behavior, CVE-2025-15556, and provided IOCs and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.