logo

Notepad++ Update Hijacking Linked to Hosting Provider Compromise

ID: e50eaca9-cff0-53c2-aed9-df9e96347e62

STIX ID: report--e50eaca9-cff0-53c2-aed9-df9e96347e62

Feed Name: Infosecurity Magazine (News)

Threat Score
88/100

Date Published: 2026-02-02

Date Updated: 2026-04-22

...
...

A supply-chain attack against Notepad++ was carried out by compromising shared hosting infrastructure used for the project's update endpoint; attackers redirected update traffic and delivered malicious manifests/executables via the WinGUp updater. The intrusion, believed to have started in June 2025 and persisted through credential exposure until December 2025, is assessed by multiple researchers as likely Chinese state-sponsored. The hosting provider patched systems, rotated credentials, and reported no similar patterns on other servers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.