Notepad++ Updates Delivered Malware After Hosting Provider Breach
ID: 00907a61-d744-55cc-a2f7-18c676b76e9e
STIX ID: report--00907a61-d744-55cc-a2f7-18c676b76e9e
Feed Name: HackRead
Notepad++'s update infrastructure was compromised through its former hosting provider, allowing attackers to intercept update requests and redirect some users to servers delivering malicious installers from June through at least November 2025. The compromise focused on the notepad-plus-plus.org domain, exhibited selective, persistent behavior consistent with an APT, and prompted migration to a new host plus enhanced client-side verification (signature and XML digital signatures) to mitigate future hijacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
