Notepad++ Updates Hijacked by Chinese Hackers in Malware Campaign - Inspirepreneur Magazine

Notepad++ Updates Hijacked by Chinese Hackers in Malware Campaign

Feb 3, 2026 1:06 PM IST
Category America

Synopsis

Notepad++ has disclosed that its software update system was compromised in a targeted cyber-espionage campaign linked to suspected Chinese state-backed hackers. The attack, which lasted several months in 2025, involved redirecting a limited number of users to malicious update servers rather than exploiting the application’s source code. While the breach did not affect most users, it highlights growing risks tied to software supply-chain security. The project has since secured its infrastructure and released updates to prevent further misuse.

Notepad++, a widely used open-source text editor, disclosed that its software update system was compromised in a targeted cyberattack attributed to suspected Chinese state-backed hackers. The incident unfolded over several months in 2025 and involved redirecting select users to malicious update servers. The project has since secured its infrastructure, issued fixes, and advised users to update their installations immediately.

01
Chapter one

What was compromised

The attackers did not breach Notepad++’s source code or development environment. Instead, they gained unauthorised access to the third-party hosting infrastructure responsible for managing update traffic. This allowed them to intercept update requests and reroute a limited number of users to attacker-controlled servers.

Those servers delivered modified update packages that could install malware, enabling long-term access to affected systems. Investigators stressed that the campaign was narrowly targeted and did not involve mass distribution of malicious updates.

According to the Notepad++ project, the intrusion began around June 2025 and continued until December 2025. Although initial vulnerabilities in the hosting environment were addressed by early September, the attackers retained access using previously stolen credentials.

This persistence allowed the redirection of update traffic to continue for several additional weeks before the activity was fully detected and blocked. Logs reviewed after the incident confirmed repeated attempts to regain access even after remediation steps were taken.

02
Chapter two

Attribution and threat actor profile

Cybersecurity researchers have linked the operation to Lotus Blossom, a long-running espionage group associated with Chinese government interests. The group is known for low-noise campaigns focused on intelligence gathering rather than widespread disruption.

The Notepad++ breach underscores the risks inherent in software supply chains, particularly when update mechanisms rely on shared or third-party infrastructure. Users typically trust automatic updates, making such attacks difficult to detect and potentially more effective.

Notepad++ is widely used by developers, system administrators, and organisations worldwide. Even though the number of affected users appears limited, the incident raises broader concerns about update security in open-source projects and the need for stronger verification controls.

Notepad++ creator and maintainer Don Ho confirmed that the compromised hosting environment has been replaced and additional safeguards have been introduced.

The project has rolled out updates that strengthen certificate validation and improve verification of update packages. Plans are also underway to enforce stricter digital signature checks in future releases to prevent unauthorised update redirection.

Ho said there is no evidence that the majority of users were affected, but urged all users to upgrade as a precaution.

Users are advised to download the latest version of Notepad++ directly from the official website and avoid third-party mirrors. Organisations that installed updates during the affected period may consider reviewing systems for unusual activity.

03
Chapter three

key highlights

  • Notepad++ update system compromised in a targeted malware campaign
  • Attack linked to suspected Chinese state-backed hacking group
  • The hosting infrastructure was exploited, not the application source code
  • Security updates released and infrastructure migrated

Follow Inspirepreneur Magazine for the latest American breaking news.

Pooja Malik
Written by Pooja Malik

Pooja Malik is a business journalist with over six years of experience covering startups, entrepreneurship, and emerging trends. She has previously worked with leading media platforms such as YourStory Media and BW BusinessWorld, where she reported on business, policy, and market developments. Currently, she serves as Editor at The Inspirepreneur Magazine, where she writes and edits stories across business, lifestyle, and travel, with a focus on clarity, accuracy, and reader relevance.