HomeSecurityNotepad++: Update mechanism breached for malware distribution

Notepad++: Update mechanism breached for malware distribution

The maintainer of Notepad++ has revealed that state-backed hackers have compromised the tool's update mechanism to redirect update traffic to malicious servers.

Notepad++

“The attack involved an infrastructure-level breach that allowed malicious actors to intercept and redirect update traffic destined for notepad-plus-plus.org,” said developer Don Ho. “The breach occurred at the hosting provider level and not through vulnerabilities in the Notepad++ code itself.” The exact mechanism by which this occurred is under investigation.

See also: New wave of extortion attacks targeting exposed MongoDB databases

Notepad++: Previous problems

This development comes a little over a month after the release of Notepad++ version 8.8.9, which addressed an issue that resulted in traffic from WinGUp (Notepad++'s update tool) being "occasional" redirected to malicious domains, leading to the download of infected executable files.

Notepad++: Update mechanism breached for malware distribution

Specifically, the issue stemmed from the way the updater tool verified the integrity and authenticity of the downloaded update file. An attacker, who could intercept network traffic between the updater client and the update server, was able to trick the tool into downloading a different binary. It is believed that this redirection was highly targeted, with traffic from only certain users being directed to the malicious servers and downloading the malicious components.

See also: Open VSX: Supply Chain attack distributes GlassWorm via compromised dev account

The incident is estimated to have started in June 2025, more than six months before it was disclosed. Independent security researcher Kevin Beaumont revealed that Chinese hackers were exploiting the vulnerability to compromise networks and trick targets into downloading malware. In response to the security incident, the Notepad++ website has been moved to a new hosting provider.

See also: Hackers breached 200+ sites via Magento vulnerability

Notepad++: Update mechanism breached for malware distribution

“According to the former hosting provider, the shared hosting server was compromised until September 2, 2025,” Ho explained. “Even after losing access to the server, the attackers retained credentials for internal services until December 2, 2025, which allowed them to continue redirecting Notepad++ update traffic to malicious servers.”

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS