Notepad++ hack: Supply chain threats evolve
ID: 79f85f08-003a-593d-a3bc-01f0b87dc8ec
STIX ID: report--79f85f08-003a-593d-a3bc-01f0b87dc8ec
Feed Name: ReversingLabs Blog
Threat Score
Notepad++ was subject to a software supply-chain compromise beginning June 2025 when attackers who researchers link to China hijacked update requests via a shared hosting server to deliver a custom backdoor called Chrysalis; the malware provided persistent, stealthy remote access and enabled hands‑on‑keyboard intrusions, prompting Notepad++ to harden its updater, enforce certificate/signature checks, sign update XML, and move to more secure hosting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
