Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News Editorials & Other Articles General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

Eugene

(66,932 posts)
Tue Feb 3, 2026, 10:20 AM Tuesday

Notepad++ users take note: It's time to check if you're hacked

Last edited Wed Feb 4, 2026, 01:02 PM - Edit history (1)

Also: Notepad++ Hijacked by State-Sponsored Hackers (Notepad++)

credit to YouTuber SomeOrdinaryGamers for the heads up

________________________________________________

Source: Ars Technica

Notepad++ users take note: It’s time to check if you’re hacked

Suspected China-state hackers used update infrastructure to deliver backdoored version.

Dan Goodin – Feb 2, 2026 3:30 PM

Infrastructure delivering updates for Notepad++—a widely used text editor for Windows—was compromised for six months by suspected China-state hackers who used their control to deliver backdoored versions of the app to select targets, developers said Monday.

“I deeply apologize to all users affected by this hijacking,” the author of a post published to the official notepad-plus-plus.org site wrote Monday. The post said that the attack began last June with an “infrastructure-level compromise that allowed malicious actors to intercept and redirect update traffic destined for notepad-plus-plus.org.” The attackers, whom multiple investigators tied to the Chinese government, then selectively redirected certain targeted users to malicious update servers where they received backdoored updates. Notepad++ didn’t regain control of its infrastructure until December.

The attackers used their access to install a never-before-seen payload that has been dubbed Chrysalis. Security firm Rapid 7 descrbed it as a “custom, feature-rich backdoor.”

“Its wide array of capabilities indicates it is a sophisticated and permanent tool, not a simple throwaway utility,” company researchers said.

-snip-

Read more: https://arstechnica.com/security/2026/02/notepad-updater-was-compromised-for-6-months-in-supply-chain-attack/

________________________________________________

Source: Notepad++

Notepad++ Hijacked by State-Sponsored Hackers

2026-02-02

Following the security disclosure published in the v8.8.9 announcement
https://notepad-plus-plus.org/news/v889-released/
the investigation has continued in collaboration with external experts and with the full involvement of my (now former) shared hosting provider.

According to the analysis provided by the security experts, the attack involved infrastructure-level compromise that allowed malicious actors to intercept and redirect update traffic destined for notepad-plus-plus.org. The exact technical mechanism remains under investigation, though the compromise occurred at the hosting provider level rather than through vulnerabilities in Notepad++ code itself. Traffic from certain targeted users was selectively redirected to attacker-controlled malicious update manifests.

The incident began in June 2025. Multiple independent security researchers have assessed that the threat actor is likely a Chinese state-sponsored group, which would explain the highly selective targeting observed during the campaign.

An incident-response (IR) plan was proposed by the security expert, and I facilitated direct communication between the hosting provider and the IR team. After the IR team engaged with the provider and reviewed the situation, I received the following detailed statement from the provider:

Dear Customer,
We want to further update you following the previous communication with us about your server compromise and further investigation with your incident response team.
We discovered the suspicious events in our logs, which indicate that the server (where your application https://notepad-plus-plus.org/update/getDownloadUrl.php was hosted until the 1st of December, 2025) could have been compromised.
As a precautionary measure, we immediately transferred all clients’ web hosting subscriptions from this server to a new server and continued our further investigation.

-snip-

Read more: https://notepad-plus-plus.org/news/hijacked-incident-info-update/

3 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Notepad++ users take note: It's time to check if you're hacked (Original Post) Eugene Tuesday OP
Damn I love Notepad++ LearnedHand Tuesday #1
Is Notepad++ different from the Notepad that came with Windows? nt Nittersing Wednesday #2
Notepad++ is a popular open source alternative to Microsoft Notepad. Eugene Wednesday #3

Eugene

(66,932 posts)
3. Notepad++ is a popular open source alternative to Microsoft Notepad.
Wed Feb 4, 2026, 01:07 PM
Wednesday

It has additional features, especially useful for editing source code and other syntax-based text files.

... and there's no goddamned Copilot.

Latest Discussions»Help & Search»Computer Help and Support»Notepad++ users take note...