Top Stories
5 outlets·5 reports·over 19h

Notepad++ hijacked by state-sponsored actors

ThinkingNews Desk · how this was written

State-sponsored actors hijacked the Notepad++ update mechanism for six months. This compromise allowed attackers to deliver tainted software to users, creating a significant security risk. The developer and security researchers suspect the operation originated from China and may have been used to spy on targeted individuals.

Written from all 5 reports below, not from any single one.

How it was reported

  1. Hacker News·
    Notepad++ hijacked by state-sponsored actors

    Notepad++ was hijacked by state-sponsored actors. The popular text editor was compromised, potentially allowing attackers to access user data. This incident highlights a significant security risk.

  2. TechMeme·
    Notepad++ and security researchers say Chinese state-sponsored threat actors were likely behind the hijacking of its update traffic from June to December 2025 (Bill Toulas/BleepingComputer)

    Chinese state-sponsored threat actors likely hijacked Notepad++ update traffic. The hijacking occurred from June to December 2025 and lasted almost half a year. Notepad++ and security researchers made this assessment.

  3. TechCrunch·
    Notepad++ says Chinese government hackers hijacked its software updates for months

    Notepad++'s update mechanism was hijacked by Chinese government hackers. They delivered tainted software to users for months. The popular text editor's developer reported the security breach.

  4. Ars Technica·
    Notepad++ users take note: It's time to check if you're hacked

    Notepad++'s update infrastructure was compromised for six months by suspected China-state hackers. They delivered backdoored versions to select targets. The attack began in June and lasted until December.

  5. The Verge·
    Notepad++ updates got hijacked for months and could have spied for China

    Notepad++ updates were hijacked for six months, potentially spying on users. The hijacking occurred due to a vulnerability on the app's hosting provider's end. Developer Don Ho suspects a Chinese state-sponsored group was behind the attack.

Related stories

Share: