Notepad++ Updates Hijacked Through Host Compromise
Nation-state hackers hijacked Notepad++ updates by exploiting infrastructure at the app’s hosting provider, redirecting update traffic to attacker-controlled servers, according to the project’s maintainers. The incident, first detected in June 2025, did not stem from any vulnerability in Notepad++ itself but from unauthorized access at the server level hosting the updates.
Security experts found that attackers used internal credentials to reroute update data until December 2, though the malicious infrastructure appeared inactive after November 10. Analysis confirmed that only specific users were targeted in the redirection campaign, aligning with tactics often attributed to Chinese cyberespionage groups.
Following remediation, including server migration and credential rotation, the hosting provider found no further signs of compromise. Notepad++ maintainers apologized and committed to stronger security measures. The upcoming v8.9.2 release will enforce certificate checks and signature verification to prevent similar incidents.
For full details on how the Notepad++ updates were hijacked, read the official advisory at:
Nation-state hack exploited hosting infrastructure to hijack Notepad++ updates
