Notepad++ Hijacked by State-Sponsored Hackers

ivandagiant

Limp Gawd
2FA
Joined
Aug 29, 2025
Messages
290
https://notepad-plus-plus.org/news/hijacked-incident-info-update/

https://news.ycombinator.com/item?id=46851548

Not notepad++ 😭😭😭 That is an OG program

Likely Chinese state actors. Seems the attack was highly targeted, so most likely irrelevant for us this time. These supply chain attacks are getting more and more common.

TL;DR
You may be affected if you used the built in update tool on notepad++ from June 2025 to December 2025. A malicious actor was able to redirect the updater to download malicious packages from their server. Seems to be a highly targeted attack, so you are likely unaffected.
 
Last edited:
np++.jpg

/phew
 
I usually go with trusted/signed plugins for any software. Saves me the headaches.
Ya but event "trusted" source outside of Microsoft ones get comprimised because it some Dev using a single computer for Dev work , Crypto and playing cracked games :D
 
That has just as many issues with malicious plugins as well that people freely add from the marketplaces.
I'm careful about what plugins I install at home, and at work I only have one or two, just in case IT is looking.
 
I heard about this this morning from elsewhere and, in the context of asking about updates for software on my work PC and a few RD servers, told one of our network security guys about it.
 
It appeared to be targetted at Tiawanese users, and from, as the blogger I heard about this from, West Taiwan.
Do you have a link? As when I looked at the official site's article about this it didn't specify (and neither did their security film's analysis). Presumably only victims would be able tell unless someone official has made statements.
 
Maybe this is a dumb question because it is late, and I am tired, but why does a basic text editor need an update server?

It's one of the simplest programs you could ever have, and typically does nothing on the network that could open it up to vulnerabilities....
 
Maybe this is a dumb question because it is late, and I am tired, but why does a basic text editor need an update server?

It's one of the simplest programs you could ever have, and typically does nothing on the network that could open it up to vulnerabilities....
This isn't notepad, the program that comes with windows, it is a more advanced replacement. It has an update server because it is under active development and gets new features.
 
This isn't notepad, the program that comes with windows, it is a more advanced replacement. It has an update server because it is under active development and gets new features.
Understood. I have heard of Notepad++ before, though I have never used it.

I guess my take is that text editing has been done for over 50 years. What new features could there possibly be to add at this point?
 
Understood. I have heard of Notepad++ before, though I have never used it.

I guess my take is that text editing has been done for over 50 years. What new features could there possibly be to add at this point?
It's also a programmer's editor, so has syntax highlighting for a lot of languages, plugins, etc.
 
Do you have a link? As when I looked at the official site's article about this it didn't specify (and neither did their security film's analysis). Presumably only victims would be able tell unless someone official has made statements.
The only thing I have to go by is "Multiple independaent security researchers have assessed that the threat acotor is likely a Chinese state-sponsored group, which would explain the highly selective targeting obseved during the campaign."

To claim "highly selective targetting" is to suggest you know who's being targetted. Why they don't show evidence, I don't know.
 
Understood. I have heard of Notepad++ before, though I have never used it.

I guess my take is that text editing has been done for over 50 years. What new features could there possibly be to add at this point?
It also allows plugins and such and likely needs to update underlying libraries it uses, and security related things

https://notepad-plus-plus.org/news/

Example:

https://community.notepad-plus-plus.org/topic/27369/notepad-v8-9-1-release

Notepad++ v8.9.1 regression fixes, bug-fixes & new improvements:

  1. Fix EOL duplication regression when playing back old recorded macros. (Fix issue)
  2. Remedy search failure for pasted text containing trailing invisible EOL character. (Fix #17124 , #17187 )
  3. Fix customized context menu regression where separator (id=“0”) escapes FolderName submenu. (Fix #17342 )
  4. Fix issue where a single undo reverted multiple changes after macro execution. (Fix #9426 )
  5. Fix visual glitch when dragging dockable dialogs on a 2nd monitor. (Fix #16805 , #16155 , #16077 )
  6. Fix inconsistent automatic search mode switching (RegEx to Extended) in Find dialog. (Fix #17227 )
  7. Fix incorrect URL parsing caused by Unicode special spaces. (Fix #16856 )
  8. Update to Boost 1.90.0. (Implement #17326 )
  9. Improve update themes feature: fix JavaScript.js edge case. (Fix issue )
  10. Update javascript.js to better match javascript (embedded) in all themes. (Fix issue, report )
  11. Function List: enhance for Perl & PHP; add for Nim. (Fix #17382 , #17327 , implement #17377 )
  12. Fix comments and highlighting in TCL. (Fix #17315 )
  13. Update perl syntax highliging keywords and autocomplete for 5.42. (Fix #17332 )
  14. Improvement: display Find dialog status message with invisible characters warning. (Fix #17345 )
 
Back
Top