<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

Notepad++ Update System Hijacked in Months-Long Supply Chain Attack

Notepad++ faced a supply chain attack in 2025, redirecting updates to malicious servers, suspected to be by Chinese hackers.
Content Team

A sophisticated supply chain attack targeting Notepad++ users ran from June to December 2025, with attackers compromising the software's hosting provider to hijack update traffic. Instead of exploiting the code itself, hackers redirected users to malicious servers that served compromised executables through the built-in WinGUp updater.

Security analysts believe Chinese state-sponsored actors were behind the highly targeted operation, which selectively focused on Notepad++ while ignoring other customers on the shared hosting server. The attackers maintained access through exposed credentials until December 2025, even after losing direct server access in September following security updates.

The hosting provider has since rotated all credentials and patched vulnerabilities, with no other customers affected.

Source: Infosecurity Magazine

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo