Notepad++ says Chinese government hackers hijacked its software updates for months

Notepad++ says Chinese government hackers hijacked its software updates for months

The developers behind the popular open-source text editor Notepad++ have revealed that their software was hijacked to distribute malicious updates to users for several months in 2025. In a blog post, Don Ho, the creator of Notepad++, disclosed that this cyber intrusion was likely perpetrated by hackers believed to be affiliated with the Chinese government, occurring from June to December 2025, as indicated by cybersecurity experts. Ho noted that the attack demonstrated a highly selective targeting of victims, although he did not disclose the number of affected users or organizations. The specifics surrounding the extent of the breach remain uncertain, and inquiries sent to Ho had not received a response by the time of publication. Notepad++ has been a staple in the open-source community for over twenty years, with millions of downloads, including use by numerous global organizations. Security researcher Kevin Beaumont, who initially uncovered the breach, reported that a limited number of organizations, particularly those with interests in East Asia, were compromised after users inadvertently downloaded a contaminated version of the software. Beaumont explained that this breach allowed hackers to gain direct access to the computers of those running the tampered versions of Notepad++. Ho mentioned that the method of infiltration is still being investigated but provided insights into the attack's execution. The Notepad++ website was hosted on a shared server, and the attackers specifically targeted the domain to exploit a software vulnerability, redirecting some users to a malicious server they controlled. This exploitation enabled the hackers to push harmful updates to users who sought to upgrade their software until the issue was resolved in November and their access was cut off by early December. Ho confirmed that logs indicated the hackers attempted to exploit fixed vulnerabilities but were unsuccessful after the patches were applied. In light of this incident, Ho expressed his apologies and urged users to download the latest version of Notepad++, which addresses the vulnerability. This incident echoes the notorious SolarWinds cyberattack from 2019-2020, in which Russian government hackers infiltrated the company’s systems to implant a backdoor in their software, affecting various U.S. government agencies and corporations.

Sources : TechCrunch

Published On : Feb 02, 2026, 18:35

Startups
Atlassian CEO Highlights Graduate Talent Amid Job Cuts, Offering Hope for New Entrants

In a recent communication, Atlassian's CEO Mike Cannon-Brookes provided unexpected reassurance to recent graduates conce...

Business Insider | Mar 12, 2026, 17:01
Atlassian CEO Highlights Graduate Talent Amid Job Cuts, Offering Hope for New Entrants
Computing
Microsoft's Office Chief Rajesh Jha to Retire After Over 35 Years of Service

Microsoft announced on Thursday that Rajesh Jha, its prominent executive overseeing the Office division, will retire in ...

CNBC | Mar 12, 2026, 17:15
Microsoft's Office Chief Rajesh Jha to Retire After Over 35 Years of Service
Cybersecurity
Global Crackdown Dismantles Major Botnet Exploiting Home Routers

In a significant global operation, law enforcement agencies have successfully dismantled a massive botnet consisting of ...

TechCrunch | Mar 12, 2026, 17:00
Global Crackdown Dismantles Major Botnet Exploiting Home Routers
Streaming
Substack Unveils Innovative Recording Studio for Creators

Substack is making significant strides in the realm of video content with the introduction of its new Substack Recording...

TechCrunch | Mar 12, 2026, 18:45
Substack Unveils Innovative Recording Studio for Creators
Automotive
Lucid Motors Unveils Ambitious Plans for Affordable Electric SUVs

Lucid Motors is setting its sights on the bustling midsize SUV market, a move that could prove pivotal for the company's...

Ars Technica | Mar 12, 2026, 17:55
Lucid Motors Unveils Ambitious Plans for Affordable Electric SUVs
View All News