The maintainers of the widely used Windows text and code editor Notepad++ say attackers hijacked parts of the project’s official update delivery chain, selectively steering a small subset of users to malicious downloads during a months-long supply-chain operation.
Project maintainer Don Ho disclosed that the incident began around June 2025 and involved an “infrastructure-level” compromise that allowed malicious actors to intercept and redirect update-related traffic. Multiple reports describe the targeting as highly selective—suggesting the attackers aimed to stay quiet and avoid widespread detection. (The Hacker News)
What happened
Based on incident reporting and third-party investigation, the attackers did not need to modify Notepad++ source code. Instead, they abused weaknesses in the update flow—particularly around the updater component (WinGUp / “gup.exe”)—and a compromise linked to the project’s hosting environment, allowing some update checks to be redirected to attacker-controlled infrastructure. (Notepad++)
While the total number of affected users remains unclear, Cybersecurity and Infrastructure Security Agency said it is aware of the reported compromise and is investigating possible exposure across U.S. government systems.
Reuters reported that infrastructure associated with Notepad++ updates had been hosted by Hostinger in Lithuania during the relevant period.
Who is being blamed, and what the malware did
Security researchers at Rapid7 attributed the campaign (with medium confidence) to Lotus Blossom, describing it as a long-running espionage actor. Rapid7’s analysis says victims received a previously undocumented backdoor dubbed “Chrysalis”, delivered through the compromised distribution path.
Rapid7’s technical write-up describes an execution chain in which a suspicious update.exe was downloaded and executed on victim machines, dropping additional components and establishing stealthy persistence (including a hidden %AppData%\\Bluetooth\\ directory in at least one observed chain).
China’s embassy in Washington rejected claims of state involvement, saying China opposes hacking and criticizing what it called assertions made without evidence.
Fixes released and what users should do now
Notepad++ shipped update hardening in version 8.8.9 (Dec. 9, 2025) after reports that WinGUp traffic was sometimes redirected to malicious servers. In that release, the project says both Notepad++ and WinGUp were updated to verify the digital signature and certificate of installers, aborting the update if checks fail.
The project also noted that its binaries (including the installer) are digitally signed with a certificate issued by GlobalSign, and recommended removing any previously installed Notepad++ root certificate that was used in older signing arrangements. (Notepad++)
Recommended actions (practical checklist):
- Update to Notepad++ 8.8.9 or newer (or the newest available release from the official site) to ensure installer-signature verification is enforced.
- If you manage an organization: hunt for suspicious updater behavior—especially unexpected
update.exeexecution spawned from the Notepad++ updater process—and investigate any anomalies during the June–Dec 2025 window. - Consider temporarily disabling in-app auto-update in managed environments and distributing vetted installers via your standard software deployment tools until internal review is complete (common supply-chain hardening practice).
Why this matters
Software updaters are an especially attractive target because they convert trust into execution: if attackers can tamper with update routing or validation, they may be able to deliver malware through a channel users are trained to trust. This incident underscores how infrastructure compromises—hosting, update manifests, and traffic routing—can be as dangerous as a code-level breach, particularly when paired with insufficient verification in the update client.
Discover more from MultiMedia
Subscribe to get the latest posts sent to your email.

Leave a Reply