Notepad++ and security researchers say Chinese state-sponsored threat actors were likely behind the hijacking of its update traffic from June to December 2025
Chinese state-sponsored threat actors were likely behind the hijacking of Notepad++ update traffic last year that lasted for almost half a year …
Notepad++ users and administrators that relied on its update traffic during the June-to-December 2025 window must treat that delivery path as a security-review priority.
The likely state-sponsored attribution raises the incident from a product-maintenance failure to a potential espionage-focused compromise of a trusted distribution channel.
Second-order effects
Organizations using third-party updater infrastructure are likely to put more weight on independently verifying update provenance and monitoring delivery traffic, not just vendor release notices.
Security teams will reassess smaller, widely deployed developer and utility applications as potential access points, extending supplier-risk scrutiny beyond major software vendors.
Third-order effects
If attacks on update channels continue, software trust will increasingly depend on verifiable build and distribution controls rather than the reputation of the publisher alone.
State-linked campaigns may keep shifting toward software supply chains because a compromised distribution path can concentrate access to many downstream targets; the scale of that shift remains dependent on defenders' ability to harden those channels.
The trend: This is one data point in the continued use of trusted software distribution paths as high-leverage targets in state-linked cyberespionage campaigns.
Chat, no big deal. It turns out Notepad++ was compromised at the infrastructure level and if you downloaded or updated Notepad++ after September, 2025 or before December, 2025, an unknown state-sponsored actor has compromised your machine. https://notepad-plus-plus.org/ ...
interesting.... people use notepad++ because it has features they need/want. hanging enterprise environments isn't simple. people on the internet massively over simplify things....
Interesting. A good reminder that you probably want to uninstall applications that you don't really need. Especially if they have the ability to auto update.
This is bad because the compromise didn't happen inside Notepad++ itself. The attackers went after the infrastructure that delivers updates, which means the trust model was broken, not the code. Users could do everything right and still be exposed. Once update traffic is
Look, we all look the other way as the Chinese steals wood & minerals from Brazilian land and annihilates most fish species from the Chilean Pacific coastline... but Notepad++? This is where I draw the line! 😠
For convenience: I wrote a small collector that pulls all SHA-256, SHA-1 and MD5 hashes from Notepad++ releases and compiles them into big CSV + JSON files Use it to check if any Notepad++ installs in your org match known-good release hashes - and spot weird/malicious outliers [i…
The dark side of auto-updates: https://notepad-plus-plus.org/ ... Don't get me wrong, they are *essential* for some software, but the pendulum might have swung too far, adding risk where little risk existed before.
Notepad++ compromised in supply chain attack from June to December 2025 by “likely Chinese state-sponsored actor”. There has been a rash of supply chain incidents over the last couple of years as these guys try to leapfrog into hard targets. https://notepad-plus-plus.org/ ...
Popular Text Editor Notepad++ was compromised by a nation state attacker presumably from June through December 2, 2025. The state actor used the access to reroute software update traffic to attacker controlled servers making this a supply chain attack. https://notepad-plus-plus.o…
Oh no. I'm a little confused as to which versions are affected so if anyone can find it, please let me know. I have to let 42,000 people know what to do. 🤦♀️ Thanks for the wake up call, Florian!!! 😜
‘The incident began from June 2025. Multiple independaent security researchers have assessed that the threat acotor is likely a Chinese state-sponsored group, which would explain the highly selective targeting obseved during the campaign.’ #NotepadPlusPlus #Notepad #Compromised […
Notepad++ publishes a blog post saying they caught a probably-Chinese state actor hijacking their product in an attack against highly-selective targets that began last June: notepad-plus-plus.org/news/hijacke...
RE: https://infosec.exchange/... In brief, the recommendation is to download the complete installer for Notepad++ version 8.9.1 and run it to replace whatever version you currently have installed. The built-in auto-updater will have new security enhancements to prevent any more…
Good thing we got rid of our cybersecurity agencies in this country. — I'm going to go out on a limb and say probably 90% of developers have this application installed. — techcrunch.com/2026/02/02/n...