Frequently Asked Questions About Notepad++ Supply Chain Compromise
ID: 418f244f-a903-5e8c-b427-40f27cf19b87
STIX ID: report--418f244f-a903-5e8c-b427-40f27cf19b87
Feed Name: Security Boulevard
Threat Score
**Notepad++ supply-chain compromise:** Beginning in June 2025, threat actors compromised the infrastructure used to distribute Notepad++ updates, redirecting update traffic to an attacker-controlled site for targeted espionage; reports attribute the activity to the Chinese APT Lotus Blossom, and Notepad++ issued version 8.9.1 to add XML signature validation as a mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
