Notepad++ Infrastructure Hijacked in State-Linked Supply Chain Attack
ID: 010e9ab0-7d46-5eec-bef1-16b278ed96d4
STIX ID: report--010e9ab0-7d46-5eec-bef1-16b278ed96d4
Feed Name: SOCRadar Blog
Notepad++ disclosed an infrastructure-level supply-chain compromise at a shared hosting provider (June–December 2025) where attackers selectively redirected update traffic to attacker-controlled servers, delivering a malicious NSIS installer that side-loaded a DLL and deployed the "Chrysalis" backdoor; the operation is attributed with medium confidence to the Chinese-linked APT "Lotus Blossom." Notepad++ migrated hosting, released v8.8.9 with improved certificate/installer signature verification and plans mandatory XMLDSig validation; the report provides file hashes, network indicators, and ATT&CK mappings for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
