| Document Title |
|---|
| Notepad++ update hijack: what the six-month breach teaches about updater trust | |
|
|---|
| BleepingComputer reports Notepad++ update traffic was hijacked in 2025, with selective redirects to malicious servers and later attribution to a Chinese state-linked actor. Here’s what failed, what was fixed, and how orgs can harden software distribution. | |
| Title Attribute |
|---|
| oEmbed (JSON) | |
| oEmbed (XML) | |
| JSON | |
| View all posts by Admin | |
| Microsoft says a Windows update bug can prevent shutdown—what’s affected and the workaround | |
| The Arctic is getting louder and narwhals are getting quieter: why underwater noise matters | |
| Page Content |
|---|
| Notepad++ update hijack: what the six-month breach teaches about updater trust | |
| Nature | |
| Climate | |
| / | |
| Technology | |
| / By | |
| Admin | |
| Notepad++ says its update traffic was hijacked for months in 2025, with attackers intercepting and selectively redirecting some users to malicious infrastructure. BleepingComputer reports the compromise began in June 2025 and ended on December 2, after the hosting provider detected the breach and cut off access. | |
| The incident is a useful reminder that “download over HTTPS” is not a complete security story. Update systems need strong, end-to-end verification—because the infrastructure you trust can be the thing that gets compromised. | |
| What the attackers exploited | |
| BleepingComputer describes a gap in update verification controls in older Notepad++ versions, enabling attackers to serve tampered update manifests and redirect downloads. | |
| The campaign was reportedly narrow and selective, consistent with an actor that cares more about access to specific targets than mass distribution. | |
| The timeline matters: | |
| Initial compromise in June 2025 | |
| Temporary disruption in early September after kernel/firmware updates | |
| Continued access via stolen internal credentials until December 2 | |
| That “credentials survived remediation” step is a classic incident-response failure: patching the server isn’t enough if the attacker already has keys. | |
| What Notepad++ changed after the incident | |
| BleepingComputer reports Notepad++ migrated clients to a new hosting provider, rotated credentials, and improved verification. | |
| Starting with version 8.8.9, WinGUP: | |
| Verifies installer certificates and signatures | |
| Uses cryptographically signed update XML | |
| The project also plans to enforce mandatory certificate signature verification in version 8.9.2. | |
| That progression—optional checks → stronger checks → mandatory checks—is exactly how software distribution should harden over time. | |
| The malware angle: Chrysalis and attribution | |
| BleepingComputer references Rapid7 research attributing a related campaign to a Chinese APT group known as Lotus Blossom (also described with other aliases) and a custom backdoor Rapid7 named “Chrysalis.” | |
| In targeted supply-chain incidents, the payload is often bespoke. That’s why the key defense is not “detect this exact malware,” but “make it hard to deliver any unauthorized payload through the updater.” | |
| What organizations should do differently | |
| If you manage software in an enterprise environment, this incident points to a few defensive defaults: | |
| Avoid consumer auto-updaters | |
| on critical systems where possible. | |
| Use managed software distribution | |
| (signed packages in internal repos, Intune/SCCM, etc.). | |
| Pin and verify signatures | |
| for installers and updates. | |
| Monitor “update paths” | |
| as critical infrastructure: DNS, TLS inspection policies, proxy behavior, and endpoint execution chains. | |
| If you’re an individual user, the practical steps are simpler: | |
| Update to a current Notepad++ version from the official site | |
| Be suspicious of update prompts that don’t look like the normal installer | |
| Avoid “download now” ads in search results that mimic official pages | |
| Bottom line | |
| Notepad++’s six-month update hijack wasn’t about a single bug—it was about trust boundaries. If an attacker can alter the manifest or the signature checks are weak, “updates” become remote code execution by design. The fix is end-to-end verification you can’t bypass, even when the hosting provider gets owned. | |
| Sources | |
| https://www.bleepingcomputer.com/news/security/notepad-plus-plus-update-feature-hijacked-by-chinese-state-hackers-for-months/ | |
| https://notepad-plus-plus.org/news/hijacked-incident-info-update/ | |
| https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/ | |
| ← | |
| Previous Post | |
| Next Post | |
| → | |
| oEmbed (JSON) | |
| oEmbed (XML) | |
| JSON | |
| View all posts by Admin | |
| Microsoft says a Windows update bug can prevent shutdown—what’s affected and the workaround | |
| The Arctic is getting louder and narwhals are getting quieter: why underwater noise matters | |
| BleepingComputer reports Notepad++ update traffic was hijacked in 2025, with selective redirects to malicious servers and later attribution to a Chinese state-linked actor. Here’s what failed, what was fixed, and how orgs can harden software distribution. | |
| |