Notepad++ Official Update Mechanism Hijacked to Deliver Malware to Select Users
ID: 8ae95600-1664-52a5-9b8e-ed219766ebf5
STIX ID: report--8ae95600-1664-52a5-9b8e-ed219766ebf5
Feed Name: The Hacker News
Notepad++'s update infrastructure was compromised at the hosting-provider level, allowing state-sponsored actors (attributed to Violet Typhoon/APT31) to intercept and redirect selective update traffic to malicious servers and deliver poisoned executables. The campaign, active from around June 2025 and persisting through credential retention into December 2025, targeted telecommunications and financial organizations in East Asia; Notepad++ has migrated hosting and hardened its updater to remediate the issue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
