logo

Notepad++ fixes flaw that let attackers push malicious update files

ID: 74bc8e5f-9e56-59a1-94f7-64179c9f1dcb

STIX ID: report--74bc8e5f-9e56-59a1-94f7-64179c9f1dcb

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-12-11

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Notepad++'s WinGUp updater was implicated in targeted incidents where a spawned AutoUpdater.exe collected system reconnaissance (netstat, systeminfo, tasklist, whoami) and exfiltrated the output to temp.sh; investigators suspect either update-URL hijacking or malicious installers distributed via malvertising. Notepad++ released versions 8.8.8 and 8.8.9 to restrict update sources and require signed installers while the investigation into the exact hijack method continues.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.