The maintainer of Notepad++ has revealed that state-backed hackers have compromised the tool's update mechanism to redirect update traffic to malicious servers.

“The attack involved an infrastructure-level breach that allowed malicious actors to intercept and redirect update traffic destined for notepad-plus-plus.org,” said developer Don Ho. “The breach occurred at the hosting provider level and not through vulnerabilities in the Notepad++ code itself.” The exact mechanism by which this occurred is under investigation.
See also: New wave of extortion attacks targeting exposed MongoDB databases
Notepad++: Previous problems
This development comes a little over a month after the release of Notepad++ version 8.8.9, which addressed an issue that resulted in traffic from WinGUp (Notepad++'s update tool) being "occasional" redirected to malicious domains, leading to the download of infected executable files.

Specifically, the issue stemmed from the way the updater tool verified the integrity and authenticity of the downloaded update file. An attacker, who could intercept network traffic between the updater client and the update server, was able to trick the tool into downloading a different binary. It is believed that this redirection was highly targeted, with traffic from only certain users being directed to the malicious servers and downloading the malicious components.
See also: Open VSX: Supply Chain attack distributes GlassWorm via compromised dev account
The incident is estimated to have started in June 2025, more than six months before it was disclosed. Independent security researcher Kevin Beaumont revealed that Chinese hackers were exploiting the vulnerability to compromise networks and trick targets into downloading malware. In response to the security incident, the Notepad++ website has been moved to a new hosting provider.
See also: Hackers breached 200+ sites via Magento vulnerability

“According to the former hosting provider, the shared hosting server was compromised until September 2, 2025,” Ho explained. “Even after losing access to the server, the attackers retained credentials for internal services until December 2, 2025, which allowed them to continue redirecting Notepad++ update traffic to malicious servers.”
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
