Temporary Advertisements:
Ad
Ad
Ad
Notepad++ Update Hijack – State-Sponsored Attack
by czx - Saturday February 14, 2026 at 03:04 PM
#1
[IMG width="347px"]https://notepad-plus-plus.org/images/logo.svg[/IMG]

NotePad++

Between June and December 2025, the Notepad++ update infrastructure was compromised due to a shared hosting provider breach. Attackers, likely a Chinese state-sponsored group, intercepted and redirected update traffic to serve malicious installers to targeted users.

The Notepad++ code itself was not vulnerable; the compromise occurred at the hosting level. Attackers maintained credentials to internal services even after losing direct server access, allowing selective traffic redirection until December 2, 2025.

Mitigations:

The Notepad++ website was migrated to a new, secure hosting provider.
WinGup (updater) now verifies both certificates and signatures of downloaded installers.
XML update manifests are digitally signed (XMLDSig), enforced in upcoming releases.
Users were advised to install v8.9.1+ manually to ensure safe updates.

This incident highlights the risks of supply chain attacks: even trusted software can be hijacked if hosting or update infrastructure is compromised.

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Contact Administration.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Breached forums and clones? fda5b 7 3,039 Sep 07, 2026, 04:55 PM
Last Post: ShinyHunters
  Claude Mythos biyukean 7 983 Sep 05, 2026, 03:33 PM
Last Post: fkcca
  BreachForums Leak Free Data KingJulien 187 19,693 Sep 02, 2026, 09:50 PM
Last Post: kh3rnz
  Breached.hn Closes with Apologies Dissent Doe 1 1,414 Sep 02, 2026, 02:31 PM
Last Post: suicided
  Fortnite cubotw0 1 706 Sep 02, 2026, 11:41 AM
Last Post: loost

Forum Jump:


 Users browsing this forum: