logo

Notepad++ Official Update Mechanism Hijacked to Deliver Malware to Select Users

ID: 8ae95600-1664-52a5-9b8e-ed219766ebf5

STIX ID: report--8ae95600-1664-52a5-9b8e-ed219766ebf5

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-02-02

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Notepad++'s update infrastructure was compromised at the hosting-provider level, allowing state-sponsored actors (attributed to Violet Typhoon/APT31) to intercept and redirect selective update traffic to malicious servers and deliver poisoned executables. The campaign, active from around June 2025 and persisting through credential retention into December 2025, targeted telecommunications and financial organizations in East Asia; Notepad++ has migrated hosting and hardened its updater to remediate the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.