Notepad++ update feature hijacked by Chinese state hackers for months
ID: c2663347-59b7-53a7-99dc-deca3f2e5a9a
STIX ID: report--c2663347-59b7-53a7-99dc-deca3f2e5a9a
Feed Name: Bleeping Computer
Notepad++'s update infrastructure was compromised between June and December 2025, allowing attackers to selectively redirect update requests to malicious servers and serve tampered update manifests. Independent researchers and Rapid7 attribute the activity to Chinese state-sponsored APT Lotus Blossom, which deployed a custom backdoor named Chrysalis; Notepad++ patched WinGup update verification, migrated hosting, rotated credentials, and advised users to change credentials and update software. The incident demonstrates a targeted supply-chain exploitation with persistent backdoor capabilities despite limited public IoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
