logo

Notepad++ Updates Delivered Malware After Hosting Provider Breach

ID: 00907a61-d744-55cc-a2f7-18c676b76e9e

STIX ID: report--00907a61-d744-55cc-a2f7-18c676b76e9e

Feed Name: HackRead

Threat Score
85/100

Date Published: 2026-02-02

Date Updated: 2026-04-22

Author: Waqas

...
...

Notepad++'s update infrastructure was compromised through its former hosting provider, allowing attackers to intercept update requests and redirect some users to servers delivering malicious installers from June through at least November 2025. The compromise focused on the notepad-plus-plus.org domain, exhibited selective, persistent behavior consistent with an APT, and prompted migration to a new host plus enhanced client-side verification (signature and XML digital signatures) to mitigate future hijacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.