Nation-state hack exploited hosting infrastructure to hijack Notepad++ updates

Notepad++ maintainer says nation-state attackers hijacked the app’s update system by redirecting traffic at the hosting provider level.

The Notepad++ maintainer revealed that nation-state hackers compromised the hosting provider’s infrastructure, redirecting update traffic to malicious servers. The attack did not exploit flaws in Notepad++ code but intercepted updates before they reached users.

Nation-state hack exploited hosting infrastructure to hijack Notepad++ updates

“According to the analysis provided by the security experts, the attack involved infrastructure-level compromise that allowed malicious actors to intercept and redirect update traffic destined for notepad-plus-plus.org.” reads the advisory published by the software maintainers. “The exact technical mechanism remains under investigation, though the compromise occured at the hosting provider level rather than through vulnerabilities in Notepad++ code itself. Traffic from certain targeted users was selectively redirected to attacker-controlled served malicious update manifests.”

The incident began in June 2025 and was linked by multiple researchers to a likely Chinese state-sponsored group, based on its highly selective targeting. Attackers compromised a shared hosting server until September 2, 2025, and later used stolen internal credentials to redirect Notepad++ update traffic to malicious servers until December 2.

The hosting provider moved all affected customers to a new server, fixed the vulnerabilities that were abused, and rotated all credentials that may have been exposed.


What do you think? Post a comment.


After completing these actions, the provider reviewed system logs and confirmed there was no evidence of continued attacker access or malicious activity.

The security expert found the attack ended on November 10, 2025, while the hosting provider reported possible attacker access until December 2. Combining both assessments, the compromise likely lasted from June to December 2, 2025.

- Advertisement -

EXPLORE MORE

US-Backed SDF Leader Joins Sharaa Regime As Presidential Advisor After Kurdish Force Dissolved

Via The Cradle Self-proclaimed Syrian President Ahmad al-Sharaa has appointed Kurdish leader…

USAF Approves FQ-42 & FQ-44 Collaborative Combat Aircraft

The U.S. Air Force has officially approved the General Atomics FQ-42 Vengeance…

Nidec scandal sends bonds to bottom in test for new CEO

Scandal-tainted Nidec, which grew from a Kyoto startup into the world’s largest…

Fighter, fighter-bomber and attack aviation of Yugoslavia, Serbia and Croatia

In the late 1950s, there was a reconciliation between Yugoslav leader Josip…

China-linked APT UNC3886 targets Singapore telcos

China-linked group UNC3886 targeted Singapore ’s telecom sector in a cyber espionage…

Ukraine’s STING S Downs Jet-Powered Geran-5 as Drone Air Defense Enters New Race

Ukraine’s 1020th Anti-Aircraft Missile Regiment publicly documented a combat interception of a…

The maintainers apologized to affected users and moved the Notepad++ site to a more secure hosting provider. The updater was strengthened to verify installer certificates and signatures, with signed update data and stricter checks fully enforced in the upcoming v8.9.2 release.

“The security exper’s analysis indicates the attack ceased on November 10, 2025, while the hosting provider’s statement shows potential attacker access until December 2, 2025.” concludes the advsory. “Based on both assessment, I estimate the overall compromise period spanned from June through December 2, 2025, when all attacker access was definitively terminated.”

Pierluigi Paganini



Share This Article

CONVERSATION

Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted

Russia Issues Final Warning to West as Dobropillia Becomes a Critical New Cauldron

The geopolitical landscape of Eastern Europe stands at a…

Canada MAID Program: Truth About the 16,000 Assisted Deaths

A striking narrative has taken center stage in global…

Germany's Former Spy Chief Arrested In Biggest Espionage Scandal Of The Century

August Hanning, former head of the German BND foreign…

Interesting…

The vast and ever-expanding universe of Star Wars continues…

Congressman Scott Perry Exposes Major Washington Overreach During Live TeleTown Hall

Rep. Scott Perry (R-PA) recently connected with constituents across…