Notepad++ says Chinese government hackers hijacked its software updates for months
ID: b63b86e6-2601-5bf3-9178-5c6431ea6f3c
STIX ID: report--b63b86e6-2601-5bf3-9178-5c6431ea6f3c
Feed Name: TechCrunch Security News
Notepad++ confirmed that attackers hijacked its update mechanism between June and December 2025 by exploiting a bug in its hosted website to redirect some users to a malicious server and deliver tainted updates; security researchers attribute the campaign to actors linked to the Chinese government and say a small number of organizations with interests in East Asia were targeted. The vulnerability was fixed in November, access terminated in early December, and users are urged to install the latest Notepad++ release.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
