Notepad++ updates were hijacked for months to deliver malware to chosen targets

Reading Time: 5 min
18
techkahwa.net | 3 February 2026

The Notepad++ project has disclosed that attackers compromised the shared hosting server behind its website and used it to intercept and redirect update traffic from June to December 2025. The targeting was selective and not every user was hit, but the advice for everyone is the same: manually install Notepad++ 8.9.1 or later from the official site.

What happened

In a notice published on 2 February 2026, the Notepad++ project explained that a shared hosting server it relied on had been compromised. That gave the attackers the ability to intercept update traffic and redirect it, so some users who clicked “update” could be served something other than the genuine release.

According to the project, the compromise began in June 2025 and lasted until 2 December 2025, when the attackers’ access was terminated. The hosting provider also said the attackers “maintained the credentials of our internal services,” a reminder that cutting off server access is only part of the clean-up.

One detail from the hosting provider stood out to me. The attackers “specifically searched for https://notepad-plus-plus.org/ domain.” In other words, this was not a random break-in that happened to catch Notepad++. Someone went looking for this particular project, most likely because a trusted, widely used tool with a built-in updater is a very efficient way to reach specific people.

Who is affected

Not every Notepad++ user was infected, and it would be wrong to suggest otherwise. The notice quotes researchers who describe the targeting as “highly selective,” meaning the attackers chose which users would receive a malicious update.

On who might be behind it, researchers quoted by the project say “the threat actor is likely a Chinese state-sponsored group, which would explain the highly selective targeting.” The security firm Rapid7 has linked the activity to a group it tracks as Lotus Blossom and to a backdoor it calls Chrysalis. These are assessments by researchers, not proven facts, and the word “likely” in that quote is doing real work.

For an ordinary user, the practical question is simpler. If you use Notepad++ and rely on its built-in updater, you should make sure you are on a safe version installed from a verified source. Organisations, especially those that might be of interest to a state-backed group, have more reason to investigate further.

By the numbers

Item Detail Source
Compromise began June 2025 Notepad++
Attacker access terminated 2 December 2025 Notepad++
Public disclosure 2 February 2026 Notepad++
Version that added certificate and signature checks to WinGup 8.8.9 Notepad++
Version users should install manually 8.9.1 Notepad++
Version that will enforce XML signature verification 8.9.2 Notepad++
Suspected group, per Rapid7’s assessment Lotus Blossom Rapid7
Backdoor named by Rapid7 Chrysalis Rapid7

What to do now

These steps come from the Notepad++ notice and Rapid7’s guidance.

  1. Download Notepad++ 8.9.1 or later only from the official website, notepad-plus-plus.org, and install it manually rather than through the built-in updater.
  2. Before running the installer, check its digital signature to confirm it comes from the Notepad++ project.
  3. If you run IT for an organisation, hunt for the indicators of compromise that Rapid7 published in its report.
  4. Keep an inventory of the software your team uses, including which tools update themselves and from where. You cannot check what you do not know is there.

Version 8.8.9 already added certificate and signature checks to WinGup, the updater Notepad++ uses, and the project says 8.9.2 will go further by enforcing XML signature verification. That direction is right. Updates should prove where they came from before anything is installed.

Why it matters

We tell people to keep software updated, and that advice still stands. This incident shows the other side of it: the update channel itself is part of the supply chain, and if the server behind it is weak, the update button becomes a delivery route.

What I take from this case is not “stop updating.” It is that signatures and verification matter, both for the developers who ship software and for the people who install it. Free, much-loved tools rarely have the security budget of a large company, and this case shows that hosting choices and update checks are exactly where a determined attacker will look.

Sources

  • Notepad++, notice on the hijacked update incident, 2 February 2026, https://notepad-plus-plus.org/news/hijacked-incident-info-update/
  • Rapid7, research on the Chrysalis backdoor and the Lotus Blossom toolkit, February 2026, https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/
  • The Register, report on the Notepad++ update hijacking and Rapid7’s Lotus Blossom link, 2 February 2026, https://www.theregister.com/2026/02/02/notepad_hijacking_lotus_blossom/