<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

Chinese Hackers Hijacked Notepad++ Updates Through Hosting Provider Compromise

Chinese hackers targeted Notepad++ users in a sophisticated supply chain attack, compromising updates and affecting telecoms in East Asia.
Content Team

Chinese state-sponsored hackers conducted a sophisticated supply chain attack against Notepad++ users from June to December 2025, targeting telecoms and financial firms in East Asia. The attackers compromised the text editor's hosting provider to intercept and redirect update traffic to malicious servers.

Creator Don Ho revealed that hackers gained infrastructure-level access to selectively target specific users while leaving others unaffected. The hosting provider discovered the breach affected only Notepad++ traffic, with attackers maintaining access until December 2025 despite server maintenance in September.

Notepad++ has since moved to a new hosting provider and added client-side verification to prevent future update hijacking.

Source: Security Week

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo