Cyber Attacks

Notepad++ update traffic hijacked in supply chain attack

0

Notepad++ has released further details about a supply chain attack uncovered in December 2025, revealing that a likely Chinese state-sponsored threat actor targeted a small number of users by compromising the project’s hosting provider.

The incident came to light after Notepad++ issued updates to prevent its software updater from being hijacked. Earlier in December, security researcher Kevin Beaumont disclosed that several organizations had received malicious updates through Notepad++, with the activity traced to China-linked hackers targeting telecom and financial services companies in East Asia.

Following a joint investigation with external security experts and the affected shared hosting provider, Notepad++ creator and maintainer Don Ho confirmed that the attack did not stem from vulnerabilities in Notepad++ itself. Instead, attackers compromised infrastructure at the hosting provider level, enabling them to intercept and redirect update traffic intended for notepad-plus-plus.org.

According to Ho, only traffic from selected targets was redirected to attacker-controlled servers hosting malicious update manifests, indicating highly selective targeting. Multiple independent researchers have assessed that the operation was likely conducted by a Chinese government–sponsored group.

The hosting provider’s investigation found no evidence that other customers on the shared server were affected. The compromise is believed to have begun in June 2025 and persisted until September 2, when scheduled maintenance updated the server’s kernel and firmware. However, credentials stolen prior to that date allowed the attackers to retain access to internal systems until December 2, during which time they continued redirecting Notepad++ update traffic to deliver malware.

In response, Notepad++ has migrated to a new hosting provider and introduced client-side measures to verify the integrity of software updates, aiming to prevent similar attacks in the future.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

eScan confirms unauthorized update after Server breach

Previous article

NationStates shuts down after data breach

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *