logo

Notepad++ hack: Supply chain threats evolve

ID: 79f85f08-003a-593d-a3bc-01f0b87dc8ec

STIX ID: report--79f85f08-003a-593d-a3bc-01f0b87dc8ec

Feed Name: ReversingLabs Blog

Threat Score
88/100

Date Published: 2026-02-05

Date Updated: 2026-04-29

Author: Paul Roberts

...
...

Notepad++ was subject to a software supply-chain compromise beginning June 2025 when attackers who researchers link to China hijacked update requests via a shared hosting server to deliver a custom backdoor called Chrysalis; the malware provided persistent, stealthy remote access and enabled hands‑on‑keyboard intrusions, prompting Notepad++ to harden its updater, enforce certificate/signature checks, sign update XML, and move to more secure hosting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.