Notepad++ hijacked by state-sponsored actors

ThinkingNews Desk · how this was written
State-sponsored actors hijacked the Notepad++ update mechanism for six months. This compromise allowed attackers to deliver tainted software to users, creating a significant security risk. The developer and security researchers suspect the operation originated from China and may have been used to spy on targeted individuals.
Written from all 5 reports below, not from any single one.
How it was reported
- Hacker News·Notepad++ hijacked by state-sponsored actors
Notepad++ was hijacked by state-sponsored actors. The popular text editor was compromised, potentially allowing attackers to access user data. This incident highlights a significant security risk.
- TechMeme·Notepad++ and security researchers say Chinese state-sponsored threat actors were likely behind the hijacking of its update traffic from June to December 2025 (Bill Toulas/BleepingComputer)
Chinese state-sponsored threat actors likely hijacked Notepad++ update traffic. The hijacking occurred from June to December 2025 and lasted almost half a year. Notepad++ and security researchers made this assessment.
- TechCrunch·Notepad++ says Chinese government hackers hijacked its software updates for months
Notepad++'s update mechanism was hijacked by Chinese government hackers. They delivered tainted software to users for months. The popular text editor's developer reported the security breach.
- Ars Technica·Notepad++ users take note: It's time to check if you're hacked
Notepad++'s update infrastructure was compromised for six months by suspected China-state hackers. They delivered backdoored versions to select targets. The attack began in June and lasted until December.
- The Verge·Notepad++ updates got hijacked for months and could have spied for China
Notepad++ updates were hijacked for six months, potentially spying on users. The hijacking occurred due to a vulnerability on the app's hosting provider's end. Developer Don Ho suspects a Chinese state-sponsored group was behind the attack.
Related stories
- Windows Notepad App Remote Code Execution Vulnerability3 outlets
- OpenAI agents hijacked German website in previously undisclosed AI breakout7 outlets
- Sources: OpenAI found ~24 incidents of its agents acting in undesirable ways as of mid-September; OpenAI says its agents leaked 53 images from ChatGPT users (Reuters)4 outlets
- Dangerous New Linux Exploit Gives Attackers Root Access to Countless Computers3 outlets