The popular source code editor Notepad++ was the target of a sophisticated one for over half a year Supply chain attack. Attackers hijacked the update mechanism to specifically distribute spy software.
The developers confirmed in early February 2026 that hackers had compromised an external hosting provider from June to December 2025. They used this access to redirect update requests and thus smuggled malware onto selected systems. The attack did not exploit a vulnerability in the Notepad++ code itself, but rather manipulated the chain of trust of software distribution – a growing problem in cybersecurity.
Attack via the hosting service provider
Table of Contents
The attack began in June 2025. The attackers gained access to the shared server of the Notepad++ project. This allowed them to specifically redirect traffic from the official Notepad++ domain to their own servers. A routine update from the host temporarily interrupted direct server access on September 2, 2025.
Advertisement
Supply chain attacks like this highlight how dangerous unsecured update mechanisms can be. A free cybersecurity report explains current attack scenarios — from manipulated update routes to targeted espionage tools — and provides practical steps that IT teams can use to immediately harden update verifications, signature checks and endpoint logs. Includes a checklist to secure update processes for companies of all sizes. Download the free cyber security report now
But with stolen access data, the hackers continued the redirection – until the final access stop on December 2, 2025. The malware disguised itself as a legitimate update. This was made possible by inadequate checks of signatures and certificates WinGUp-Auto-Updater versions 8.8.9 and older.
Targeted espionage instead of mass attacks
Unlike ransomware attacks, this was a precise espionage operation. Security researchers only found about a dozen infected systems. The victims: government departments in the Philippines, financial institutions, IT service providers and telecommunications companies, primarily in Southeast Asia.
Who is behind it? The security company Rapid7 orders the group’s attack Lotus Blossom to – a suspected Chinese state-backed actor known for attacks in Southeast Asia. Other researchers call the group zirconium. The tools used, such as the new “Chrysalis” backdoor or Cobalt Strike, are typical of espionage operations.
Notepad++ responds with security upgrade
As a consequence, the Notepad++ project has secured its infrastructure. The website switched to a hosting provider with stronger protections. Crucial: The update process has been fundamentally improved.
Since version 8.8.9 from December 2025, the WinGup updater checks both the certificate and the digital signature of the downloaded installation file. The upcoming version 8.9.2 is intended to further tighten the validation of the update server data. The goal: to make manipulation impossible in the future.
What does this mean for users?
The case shows the danger inherent in automatic updates. These often run in the background with elevated rights – a perfect gateway for supply chain attacks. Compromising a supplier can turn a trusted software feature into a malware peddler.
Users should have the latest version of Notepad++ manually from the official website or the GitHub repository. Organizations must review their endpoint logs for unusual Notepad++ updater activity between June and December 2025. The incident underlines: Robust verification mechanisms are vital for software updates.
PS: By the way – if you want to detect and prevent such manipulations at an early stage in the future, you will find concrete audit checklists in the same free cyber security guide: which log sources you should prioritize, how you check update servers and signature chains and which organizational measures will make life difficult for attackers in the long term. Request your free cyber security guide now
date: 2026-02-08 18:34:00
Related reading