logo

Notepad++ Hosting Breach Attributed to China-Linked Lotus Blossom Hacking Group

ID: 13cbaf74-0e93-5aed-bdd2-c7ef9cf19fcb

STIX ID: report--13cbaf74-0e93-5aed-bdd2-c7ef9cf19fcb

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-02-03

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

A China-linked APT (Lotus Blossom) compromised Notepad++'s hosting/update infrastructure between June and December 2025 to deliver a custom backdoor called "Chrysalis" via tampered NSIS installer updates; Rapid7 and Kaspersky analyses describe multiple targeted infection chains using DLL sideloading, Metasploit/Cobalt Strike loaders, rotating C2s and numerous IoCs, with observed victims across APAC, South America and Australia — the issue was fixed in version 8.8.9 and the project migrated hosting and rotated credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.