logo

Notepad++ Infrastructure Hijacked in State-Linked Supply Chain Attack

ID: 010e9ab0-7d46-5eec-bef1-16b278ed96d4

STIX ID: report--010e9ab0-7d46-5eec-bef1-16b278ed96d4

Feed Name: SOCRadar Blog

Threat Score
90/100

Date Published: 2026-02-02

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

Notepad++ disclosed an infrastructure-level supply-chain compromise at a shared hosting provider (June–December 2025) where attackers selectively redirected update traffic to attacker-controlled servers, delivering a malicious NSIS installer that side-loaded a DLL and deployed the "Chrysalis" backdoor; the operation is attributed with medium confidence to the Chinese-linked APT "Lotus Blossom." Notepad++ migrated hosting, released v8.8.9 with improved certificate/installer signature verification and plans mandatory XMLDSig validation; the report provides file hashes, network indicators, and ATT&CK mappings for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.