State-sponsored hackers' are being blamed for compromising the popular alternative to Windows Notepad over a period of six months last year.
It's believed that, between June and November 10/December 2, 2025 (independent security experts and its hosting provider ...
The hosting provider's compromise allowed attackers to deliver malware through tainted software updates for six months.
Rapid7 links China-linked Lotus Blossom to a 2025 Notepad++ hosting breach that delivered the Chrysalis backdoor via hijacked updates, fixed in v8.8.9 ...
Chinese state-sponsored threat actors were likely behind the hijacking of Notepad++ update traffic last year that lasted for almost half a year, the developer states in an official announcement today.
Attackers had specifically delivered malware to systems using the Notepad++ updater. Investigations point to state actors.
Notepad on Windows 11 is no longer the lightweight utility it once was. Learn how to replace Notepad with Microsoft Edit on Windows 11.