Notepad++ patches flaw used to hijack update system

6 Min Read

Notepad++ patched a vulnerability that attackers used to hijack its update system and deliver malware to targeted users.

Notepad++ fixed a vulnerability that allowed a China-linked APT group to hijack its update mechanism and selectively push malware to chosen targets.

- Advertisement -

In early February, the Notepad++ maintainer revealed that nation-state hackers compromised the hosting provider’s infrastructure, redirecting update traffic to malicious servers. The attack did not exploit flaws in Notepad++ code but intercepted updates before they reached users.

“According to the analysis provided by the security experts, the attack involved infrastructure-level compromise that allowed malicious actors to intercept and redirect update traffic destined for notepad-plus-plus.org.” reads the advisory published by the software maintainers. “The exact technical mechanism remains under investigation, though the compromise occured at the hosting provider level rather than through vulnerabilities in Notepad++ code itself. Traffic from certain targeted users was selectively redirected to attacker-controlled served malicious update manifests.”


What do you think? Post a comment.


The incident began in June 2025 and was linked by multiple researchers to a likely Chinese state-sponsored group, based on its highly selective targeting. Attackers compromised a shared hosting server until September 2, 2025, and later used stolen internal credentials to redirect Notepad++ update traffic to malicious servers until December 2.

- Advertisement -

EXPLORE MORE

Suspected Russian hackers deploy CANFAIL malware against Ukraine

A new alleged Russia-linked APT group targeted Ukrainian defense, government, and energy…

Darline Graham unsure about total abortion ban: ‘Let me think about it’

Darline Graham Nordone, the sister and replacement of the late longtime Republican…

Police officer arrested after using Flock cameras 717 times to track ex-wife

A police officer faces two criminal charges after being accused of using…

Missing Juvenile Quamier Underwood from the 39th District Has Returned Home

The Philadelphia Police Department is seeking the public’s assistance in locating missing…

French police storm beach to stop migrant Channel crossing (VIDEO) News

Drone footage shows officers using pepper spray and slashing an inflatable boat…

U.S. CISA adds a flaw in BeyondTrust RS and PRA to its Known Exploited Vulnerabilities catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in…

The hosting provider moved all affected customers to a new server, fixed the vulnerabilities that were abused, and rotated all credentials that may have been exposed.

After completing these actions, the provider reviewed system logs and confirmed there was no evidence of continued attacker access or malicious activity.

The security expert found the attack ended on November 10, 2025, while the hosting provider reported possible attacker access until December 2. Combining both assessments, the compromise likely lasted from June to December 2, 2025.

Rapid7 Labs and its MDR team uncovered a sophisticated campaign tied to the China-linked APT Lotus Blossom. Active since 2009, the group runs targeted espionage against government, telecom, aviation, critical infrastructure, and media organizations, mainly in Southeast Asia and Central America. The investigation traced a compromise of Notepad++ hosting infrastructure used to deploy a new custom backdoor, dubbed Chrysalis, along with stealthy loaders that abuse Microsoft Warbird to conceal malicious code execution.

“Our investigation identified a security incident stemming from a sophisticated compromise of the infrastructure hosting Notepad++, which was subsequently used to deliver a previously undocumented custom backdoor, which we have dubbed Chrysalis.” reads the report published by Rapid7.

Rapid7’s MDR team traced the initial access to the abuse of Notepad++ distribution infrastructure. Investigators saw notepad++.exe and GUP.exe run first, followed by a suspicious update.exe downloaded from an external IP. That file turned out to be an NSIS installer, a delivery method often used by Chinese APT groups. It dropped files into a hidden AppData folder and abused DLL sideloading through a renamed Bitdefender binary to decrypt and launch a custom backdoor called Chrysalis.

“Shortly after the execution of BluetoothService.exe, which is actually a renamed legitimate Bitdefender Submission Wizard abused for DLL sideloading, a malicious log.dll was placed alongside the executable, causing it to be loaded instead of the legitimate library.” continues the report. “Two exported functions from log.dll are called by Bitdefender Submission Wizard: LogInit and LogWrite.”

Notepad++ patches flaw used to hijack update system | Philly PI

The malware relied on multiple layers of obfuscation to conceal its code and make analysis harder. It used custom API hashing to avoid calling Windows functions directly and encrypted its configuration to hide key settings. After running, it set up persistence to survive reboots, collected detailed information about the infected system, and connected to a remote command-and-control server. Through this connection, attackers could run commands, move files, and take full control of compromised machines.

Chrysalis supports full remote control, including command execution, file transfer, and interactive shells. Investigators also uncovered related loaders abusing Metasploit shellcode, Cobalt Strike beacons, and even Microsoft Warbird protections, showing long-term development and a complex, multi-stage attack chain.

Researchers attribute the campaign to Lotus Blossom based on strong overlaps with prior Symantec research, including a renamed Bitdefender tool used to sideload log.dll, similar loader chains, and shared Cobalt Strike public keys across multiple samples.

Notepad++ version 8.9.2 addressed the issue by introducing a “double lock” update system that verifies both the signed installer from GitHub and the signed XML from its update server to prevent abuse.

Notepad++ patches flaw used to hijack update system | Philly PI

The release also strengthens the WinGUp auto-updater by removing libcurl.dll to block DLL side-loading, disabling insecure SSL options, and restricting plugin execution to programs signed with the same certificate.

Version 8.9.2 also addressed an Unsafe Search Path vulnerability, tracked as CVE-2026-25926 (CVSS score of 7.3), that could result in arbitrary code execution in the context of the running application.

“An Unsafe Search Path vulnerability (CWE-426) exists when launching Windows Explorer without an absolute executable path.” reads the advisory. “This may allow execution of a malicious explorer.exe if an attacker can control the process working directory. Under certain conditions, this could lead to arbitrary code execution in the context of the running application.”

Pierluigi Paganini



Share This Article

Deposition of Renowned Vaccinologist Dr. Stanley Plotkin Sparks Debate Over Historical Research Ethics

A nine-hour legal deposition featuring Dr. Stanley Plotkin—widely regarded…

‘SCARED TO DEATH’: 48 HOURS ABOARD AMERICA’S MIGHTIEST SUPERCARRIER

ATLANTIC OCEAN — From the flight deck, the view…

Wage Gains for Bottom 25% of Working Americans Are Up 5.5% – Every Week We See Real Wage Gains”

Treasury Secretary Scott Bessent was on Newsmax‘s “Rob Schmitt…

Kurt Weldon’s 9/11 Bombshell on Jimmy Dore

Former Republican Congressman Kurt Weldon—who served Pennsylvania's 7th district…

Colombia declares emergency after devastating earthquake (VIDEOS)

At least 169 people have been killed and 668…

From Track Star to WWE Champion: Inside Lainey Reid’s Rise to the Top

Whether she’s dominating in the ring on WWE’s SmackDown…

From Competitive Ballroom to Digital Stardom: The Evolution of Emily Dobson

Emily Dobson has emerged as one of Generation Z’s…

CONVERSATION

Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted