Notepad++ says Chinese government hackers hijacked its software updates for months

Notepad++ says Chinese government hackers hijacked its software updates for months

The developers behind the popular open-source text editor Notepad++ have revealed that their software was hijacked to distribute malicious updates to users for several months in 2025. In a blog post, Don Ho, the creator of Notepad++, disclosed that this cyber intrusion was likely perpetrated by hackers believed to be affiliated with the Chinese government, occurring from June to December 2025, as indicated by cybersecurity experts. Ho noted that the attack demonstrated a highly selective targeting of victims, although he did not disclose the number of affected users or organizations. The specifics surrounding the extent of the breach remain uncertain, and inquiries sent to Ho had not received a response by the time of publication. Notepad++ has been a staple in the open-source community for over twenty years, with millions of downloads, including use by numerous global organizations. Security researcher Kevin Beaumont, who initially uncovered the breach, reported that a limited number of organizations, particularly those with interests in East Asia, were compromised after users inadvertently downloaded a contaminated version of the software. Beaumont explained that this breach allowed hackers to gain direct access to the computers of those running the tampered versions of Notepad++. Ho mentioned that the method of infiltration is still being investigated but provided insights into the attack's execution. The Notepad++ website was hosted on a shared server, and the attackers specifically targeted the domain to exploit a software vulnerability, redirecting some users to a malicious server they controlled. This exploitation enabled the hackers to push harmful updates to users who sought to upgrade their software until the issue was resolved in November and their access was cut off by early December. Ho confirmed that logs indicated the hackers attempted to exploit fixed vulnerabilities but were unsuccessful after the patches were applied. In light of this incident, Ho expressed his apologies and urged users to download the latest version of Notepad++, which addresses the vulnerability. This incident echoes the notorious SolarWinds cyberattack from 2019-2020, in which Russian government hackers infiltrated the company’s systems to implant a backdoor in their software, affecting various U.S. government agencies and corporations.

Sources : TechCrunch

Published On : Feb 02, 2026, 18:35

AI
Nvidia Strikes Major Deal with SK Hynix to Secure AI Memory Supply

Nvidia has successfully forged a significant partnership with South Korea's SK Hynix to secure memory supplies essential...

CNBC | Jul 25, 2026, 05:15
Nvidia Strikes Major Deal with SK Hynix to Secure AI Memory Supply
Cybersecurity
The Elusive Phineas Fisher: The Hacktivist Who Took Down Spyware Giants

In the realm of cybersecurity, few figures are as intriguing as Phineas Fisher, a hacker who has evaded capture for near...

TechCrunch | Jul 25, 2026, 21:00
The Elusive Phineas Fisher: The Hacktivist Who Took Down Spyware Giants
Gadgets
OpenAI's Micro Keypad: A Novelty for Coders or Just a Confounding Gadget?

Last week, OpenAI made its debut in the hardware landscape with the launch of Micro, a stylish keypad designed to integr...

TechCrunch | Jul 25, 2026, 24:40
OpenAI's Micro Keypad: A Novelty for Coders or Just a Confounding Gadget?
Computing
Market Turbulence: Four Key Factors Impacting Stocks This Week

This past week has been challenging for the stock market, driven by several significant forces that have created turbule...

CNBC | Jul 25, 2026, 20:05
Market Turbulence: Four Key Factors Impacting Stocks This Week
Computing
Crisis Averted: Power Line Failure Highlights Urgent Need for Data Center Resilience

A power line failure near Washington, DC, recently showcased a significant challenge faced by the electrical grid due to...

TechCrunch | Jul 25, 2026, 13:50
Crisis Averted: Power Line Failure Highlights Urgent Need for Data Center Resilience
View All News