Notepad++ Updates Hijacked, Possibly Used for Chinese Espionage
Users of the popular text and code editor Notepad++ may have unknowingly downloaded malicious updates after the app's servers were compromised for several months last year, according to the app's developer. The compromise, which lasted from June through December 2025, potentially allowed hackers, suspected to be a Chinese state-sponsored group, to spy on users.
Don Ho, the developer of Notepad++, posted an update on Monday detailing the attack. The compromised servers were used to distribute malicious updates to unsuspecting users. The full extent of the potential damage and information compromised remains under investigation.
The incident raises concerns about the security of software supply chains and the potential for state-sponsored actors to exploit vulnerabilities for espionage purposes. Further details regarding the nature of the malicious updates and the specific data that may have been targeted have not yet been released.
Discussion
AI Experts & Community
Be the first to comment