Notepad++ says it was hijacked by Chinese state-sponsored hackers

Last year, the creator of Notepad++ rolled out an update for the text and source code editor after security experts reported that bad actors were hijacking its update mechanism to redirect traffic to malicious servers. It led to users downloading compromised executables that could infect their devices. Now, Don Ho has revealed that multiple security experts investigated the breach and determined that the threat actor “is likely a Chinese state-sponsored group.” He said it explained why experts observed highly selective targeting during the campaign and why only traffic from certain users were redirected so that they would download malicious files. It’s not clear what kind of users were specifically targeted and what the files did to their devices.

The attackers started redirecting traffic from Notepad++ to their servers sometime in June 2025, and that went on until December 2. Their method involved compromising the system at the hosting provider level, though the exact technical mechanism that allowed them to intercept traffic remains under investigation. In addition to releasing a security patch, Notepad++ also migrated to a new hosting provider with much stronger security practices. Ho now encourages anyone who wants to install the app to download version 8.9.1, which comes with the security update, and running the installer manually.

This article originally appeared on Engadget at https://www.engadget.com/apps/notepad-says-it-was-hijacked-by-chinese-state-sponsored-hackers-153000268.html?src=rss

Read more @ Engadget

Latest posts

Anthropic says it will challenge Defense Department’s supply chain risk designation in court

In a new blog post, Anthropic CEO Dario Amodei has admitted that it received a letter from the Defense Department, officially labeling it a...

What if your real computer was a super-sized Lego computer brick?

The M2x2 in action. | Image: Paul Staal In 1979 - nearly 50 years ago - Lego jazzed up its very first spaceships with an...

United Airlines can permanently ban passengers who don’t wear headphones

United Airlines has updated its "Contract of Carriage" to include a line that requires passengers to wear headphones while listening to audio and video...

Amazon.com is up and down, with login errors and prices not loading

If you're having issues shopping on Amazon or loading your playlists on Amazon Music, you're not alone. Downdetector is showing a sizable spike in...