logo

Frequently Asked Questions About Notepad++ Supply Chain Compromise

ID: 418f244f-a903-5e8c-b427-40f27cf19b87

STIX ID: report--418f244f-a903-5e8c-b427-40f27cf19b87

Feed Name: Security Boulevard

Threat Score
85/100

Date Published: 2026-02-03

Date Updated: 2026-04-22

Author: Satnam Narang

...
...

**Notepad++ supply-chain compromise:** Beginning in June 2025, threat actors compromised the infrastructure used to distribute Notepad++ updates, redirecting update traffic to an attacker-controlled site for targeted espionage; reports attribute the activity to the Chinese APT Lotus Blossom, and Notepad++ issued version 8.9.1 to add XML signature validation as a mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.