Notepad++ Update Hijacking Linked to Hosting Provider Compromise
ID: e50eaca9-cff0-53c2-aed9-df9e96347e62
STIX ID: report--e50eaca9-cff0-53c2-aed9-df9e96347e62
Feed Name: Infosecurity Magazine (News)
A supply-chain attack against Notepad++ was carried out by compromising shared hosting infrastructure used for the project's update endpoint; attackers redirected update traffic and delivered malicious manifests/executables via the WinGUp updater. The intrusion, believed to have started in June 2025 and persisted through credential exposure until December 2025, is assessed by multiple researchers as likely Chinese state-sponsored. The hosting provider patched systems, rotated credentials, and reported no similar patterns on other servers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
