logo

Notepad++ update feature hijacked by Chinese state hackers for months

ID: c2663347-59b7-53a7-99dc-deca3f2e5a9a

STIX ID: report--c2663347-59b7-53a7-99dc-deca3f2e5a9a

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-02-02

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Notepad++'s update infrastructure was compromised between June and December 2025, allowing attackers to selectively redirect update requests to malicious servers and serve tampered update manifests. Independent researchers and Rapid7 attribute the activity to Chinese state-sponsored APT Lotus Blossom, which deployed a custom backdoor named Chrysalis; Notepad++ patched WinGup update verification, migrated hosting, rotated credentials, and advised users to change credentials and update software. The incident demonstrates a targeted supply-chain exploitation with persistent backdoor capabilities despite limited public IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.