logo

Nation-State Actors Exploit Notepad++ Supply Chain

ID: 594b253a-5ef9-50a4-ace8-b7eb9f5050d5

STIX ID: report--594b253a-5ef9-50a4-ace8-b7eb9f5050d5

Feed Name: Palo Alto Networks Unit 42

Threat Score
90/100

Date Published: 2026-02-11

Date Updated: 2026-04-28

Author: Unit 42

...
...

**Executive summary:** Between June and December 2025, a state‑sponsored group known as Lotus Blossom compromised Notepad++'s update infrastructure to selectively serve malicious update manifests to high‑value targets (notably system administrators) across multiple regions and sectors, resulting in delivery of the Chrysalis backdoor (via Bitdefender DLL sideloading) and Cobalt Strike beacons (via malicious Lua scripts); the report provides IoCs, detection queries, timelines, and remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.