logo

Small numbers of Notepad++ users reporting security woes

ID: aac08cbc-a3a7-50a3-86ae-cea65e336c55

STIX ID: report--aac08cbc-a3a7-50a3-86ae-cea65e336c55

Feed Name: DoublePulsar

Threat Score
60/100

Date Published: 2025-12-02

Date Updated: 2026-04-19

Author: Kevin Beaumont

...
...

The report outlines how weaknesses in Notepad++'s update and download mechanisms (past HTTP traffic, weak certificate usage, and update chain issues) can be abused to deliver trojanised installers; it documents targeted reconnaissance activity against East Asia-linked organizations, provides indicators to watch for (gup.exe network calls, unexpected AutoUpdater.exe in TEMP, use of curl/temp.sh), and recommends updating to 8.8.8, avoiding auto-updates, and restricting updater/network access where practical.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.