Apps & Consumer
Notepad++ updates hijacked by state-backed hackers for months
Notepad++ developer Don Ho confirmed that hackers likely linked to the Chinese government hijacked software updates for months in 2025, potentially compromising users around the world.
Don Ho, the developer of the open-source text editor Notepad++, has confirmed that hackers hijacked the software to deliver malicious updates to users over the course of several months in 2025. The cyberattack campaign, which ran between June and December 2025, targeted a widely used tool that has accumulated tens of millions of downloads. Because of the software’s broad reach, the compromise of its update mechanism threatened to distribute a tainted version of the application to organizations and users around the world.
According to Ho, the cyberattack was likely carried out by Chinese government hackers, an attribution that “would explain the highly selective targeting” observed during the campaign. Security firm Rapid7 investigated the incident and attributed the hacking to Lotus Blossom, an espionage group known to work for China. Security researcher Kevin Beaumont, who first discovered the cyberattack, noted that the hackers were able to gain “hands-on” access to the computers of victims who ran the compromised software. Beaumont stated that the campaign compromised a small number of organizations with interests in East Asia.
Ho explained that the attackers “specifically targeted” the Notepad++ web domain to redirect users to a malicious server. While the “exact technical mechanism” of how the hackers initially broke into the servers remains under investigation, Ho noted that the Notepad++ website was hosted on a shared hosting server. A shared hosting server is a common web infrastructure setup where multiple websites share a single physical server and its resources, which can sometimes expose hosted sites to shared vulnerabilities. The attackers exploited a bug on this server to deliver malicious updates to certain users who requested software updates, until the bug was fixed in November and the hackers’ access was terminated in early December.
The developer has since implemented a fix to resolve the vulnerability and urged users to download the most recent version of the software. “We do have logs indicating that the bad actor tried to re-exploit one of the fixed vulnerabilities; however, the attempt did not succeed after the fix was implemented,” Ho wrote. Security experts have compared the incident to the SolarWinds cyberattack, where state-sponsored actors planted a backdoor in software updates to compromise downstream networks. The Notepad++ breach highlights similar risks to open-source supply chains, demonstrating how attackers can exploit trusted software distribution channels to gain deep access to target systems.
Why it matters
The breach of a widely used tool like Notepad++ underscores the persistent vulnerability of open-source supply chains to state-sponsored espionage, mirroring the risks seen in the SolarWinds incident.