Feb 14, 2026, 03:04 PM
[IMG width="347px"]https://notepad-plus-plus.org/images/logo.svg[/IMG]
NotePad++
Between June and December 2025, the Notepad++ update infrastructure was compromised due to a shared hosting provider breach. Attackers, likely a Chinese state-sponsored group, intercepted and redirected update traffic to serve malicious installers to targeted users.
The Notepad++ code itself was not vulnerable; the compromise occurred at the hosting level. Attackers maintained credentials to internal services even after losing direct server access, allowing selective traffic redirection until December 2, 2025.
Mitigations:
The Notepad++ website was migrated to a new, secure hosting provider.
WinGup (updater) now verifies both certificates and signatures of downloaded installers.
XML update manifests are digitally signed (XMLDSig), enforced in upcoming releases.
Users were advised to install v8.9.1+ manually to ensure safe updates.
This incident highlights the risks of supply chain attacks: even trusted software can be hijacked if hosting or update infrastructure is compromised.
NotePad++
Between June and December 2025, the Notepad++ update infrastructure was compromised due to a shared hosting provider breach. Attackers, likely a Chinese state-sponsored group, intercepted and redirected update traffic to serve malicious installers to targeted users.
The Notepad++ code itself was not vulnerable; the compromise occurred at the hosting level. Attackers maintained credentials to internal services even after losing direct server access, allowing selective traffic redirection until December 2, 2025.
Mitigations:
The Notepad++ website was migrated to a new, secure hosting provider.
WinGup (updater) now verifies both certificates and signatures of downloaded installers.
XML update manifests are digitally signed (XMLDSig), enforced in upcoming releases.
Users were advised to install v8.9.1+ manually to ensure safe updates.
This incident highlights the risks of supply chain attacks: even trusted software can be hijacked if hosting or update infrastructure is compromised.
This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Contact Administration.
Ban Reason: Contact Administration.
