Ссылка
click to show
click to show
Notepad++ hacked (allegedly by the Chinese state-sponsored group) and used to spread malware…
Update server (not the actual binaries / repository) for Notepad++ was compromised and if you used the built in update function there is a chance that you were infected with malware.
Quotes
Quote
According to the former hosting provider, the shared hosting server was compromised until September 2, 2025. Even after losing server access, attackers maintained credentials to internal services until December 2, 2025, which allowed them to continue redirecting Notepad++ update traffic to malicious servers. The attackers specifically targeted Notepad++ domain with the goal of exploiting insufficient update verification controls that existed in older versions of Notepad++. All remediation and security hardening were completed by the provider by December 2, 2025, successfully blocking further attacker activity.
My thoughts
It sucks… People who used winget or chocolatey instead of the built in update method should be safe I believe but don’t quote me on that…
Sources
https://notepad-plus-plus.org/news/hijacked-incident-info-update/