Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Heat Is an Orbital Data Center’s Greatest Foe. These Tiles Dump It at the Source.

    August 5, 2026

    The White House Is Keeping Its AI Cybersecurity Framework Secret

    August 4, 2026

    How One Startup Built a (Mostly) China-Free Robot

    August 4, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Heat Is an Orbital Data Center’s Greatest Foe. These Tiles Dump It at the Source.
    • The White House Is Keeping Its AI Cybersecurity Framework Secret
    • How One Startup Built a (Mostly) China-Free Robot
    • The 2026 R&D Benchmark Report: Waste, AI and the Race to Market
    • Is AI making us dumber? Maybe not. But our skills are at risk
    • Is This Poker Player Bluffing? The AI Thinks So
    • The Download: US robot restrictions, and ICE’s DNA grab
    • ‘Everyone Is Doing It’: The Truth About AI in Hollywood
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»How state-sponsored attackers hijacked Notepad++ updates
    Cybersecurity

    How state-sponsored attackers hijacked Notepad++ updates

    kirklandc008@gmail.comBy kirklandc008@gmail.comFebruary 2, 2026No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    How state-sponsored attackers hijacked Notepad++ updates
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Suspected Chinese state-sponsored attackers hijacked the Notepad++ update mechanism by compromising the software project’s shared hosting server and intercepting and redirecting update traffic destined for notepad-plus-plus.org, the software’s maintainer Don Ho confirmed on Monday.

    The attack timeline

    In early December 2025, security researcher Kevin Beaumont said that he knew of three organizations that have had security incidents traced back to Notepad++ processes providing the attackers initial access to the computers.

    “I’ve only talked to a small number of victims. They are orgs with interests in East Asia. Activity appears very targeted. Victims report hands on keyboard recon activity, with activity starting around two months ago,” he shared at the time.

    The attackers were able to pull off this supply chain attack by leveraging security weaknesses in Notepad++’s updater (WinGUP).

    Before version 8.8.8, which was released in mid-November 2025, the updater code was not hardened enough to make it impossible to change the source from which updates are downloaded. Since then, downloads can only be received from GitHub.

    (Also, before version 8.8.9, the updater did not validate the integrity and authenticity of the downloaded update file.)

    This state of affairs has been exploited by the attackers, who managed to intercept the network traffic between the updater client and the Notepad++ update infrastructure, to deliver and execute a malicious update instead of a benign one.

    “Because traffic to notepad-plus-plus.org is fairly rare, it may be possible to sit inside the ISP chain and redirect to a different download,” Beaumont noted in December. “To do this at any kind of scale requires a lot of resources.”

    Beaumont shared that the targeted organizations were telecommunications and financial services organizations in East Asia, and attributed the attacks to Chinese nation-state threat actors Zirconium, aka Violet Typhoon.

    The supply chain compromise apparently happened in June 2025 and, according to the software’s hosting provider, the shared hosting server remained compromised until September 2, 2025, when the attackers lost access to it after its kernel and firmware were updated.

    “Even though the bad actors have lost access to the server from the 2nd of September, 2025, they maintained the credentials of our internal services existing on that server until the 2nd of December, which could have allowed the malicious actors to redirect some of the traffic going to https://notepad-plus-plus.org/getDownloadUrl.php to their own servers and return the updates download URL with compromised updates,” the hosting provider told Dun Ho.

    “The bad actors specifically searched for https://notepad-plus-plus.org/ domain with the goal to intercept the traffic to [the Notepad++] website, as they might know the then-existing Notepad++ vulnerabilities related to insufficient update verification controls.”

    The hosting provider stated that they have fixed vulnerabilities in the shared hosting server and that the threat actors “tried to re-exploit one of the fixed vulnerabilities” and failed, which seems to suggest this is how they managed to gain access the first time.

    Advice for organizations

    Ho said that since the incident:

    • The Notepad++ website has been migrated to a new hosting provider
    • The WinGUP updater has been enhanced so it verifies both the certificate and the signature of the downloaded installer
    • The XML file containing the download URL for the update is now signed, and the certificate and signature verification will be enforced starting with the upcoming v8.9.2, to be released in a month.

    While Notepad++ is a program that’s used by IT and software development staff in many organizations around the world, it seems that this particular attack was aimed at very specific targets.

    That’s why, back in December, Beaumont advised organizations not to over react to the news, but to still check for:

    • gup.exe making network requests for other than notepad-plus-plus.org, github.com and release-assets.githubusercontent.com
    • unexpected processes spawned by the installer
    • specific files (update.exe or AutoUpdater.exe) in the user TEMP folder.

    Also, given that other attackers are often peddling malware masquerading as Notepad++, to check whether the version installed on users’ computers is legitimate.

    “If you’re a large enterprise who package manage Notepad++ and update it, you may want to block notepad-plus-plus.org or block the gup.exe process from having internet access. You may also want to block internet access from the notepad++.exe process, unless you have robust monitoring for [third-party Notepad++] extensions,” he concluded.

    Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

    attackers hijacked Notepad statesponsored updates
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    Ransomware in 2026: More groups, more victims, no slowdown

    July 26, 2026

    The 3 types of people who will excel in the AI agent era, according to tech leaders

    July 26, 2026

    Steam forum ClickFix attacks infect gamers with XMRig cryptominers

    July 26, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views

    The AirPods 4 and Lego’s brick-ified Grogu are our favorite deals this week

    October 12, 20253 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • Heat Is an Orbital Data Center’s Greatest Foe. These Tiles Dump It at the Source.
    • The White House Is Keeping Its AI Cybersecurity Framework Secret
    • How One Startup Built a (Mostly) China-Free Robot
    • The 2026 R&D Benchmark Report: Waste, AI and the Race to Market
    • Is AI making us dumber? Maybe not. But our skills are at risk

    Heat Is an Orbital Data Center’s Greatest Foe. These Tiles Dump It at the Source.

    August 5, 2026

    The White House Is Keeping Its AI Cybersecurity Framework Secret

    August 4, 2026

    How One Startup Built a (Mostly) China-Free Robot

    August 4, 2026

    The 2026 R&D Benchmark Report: Waste, AI and the Race to Market

    August 4, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.