A critical vulnerability in the Notepad++ update mechanism, specifically within the WinGUp updater, allowed attackers to intercept and manipulate network traffic, redirecting update requests to malicious servers. This flaw enabled the silent installation of malware on user systems under the guise of legitimate software updates. Security researchers observed suspicious traffic patterns and confirmed that, in some cases, compromised binaries were delivered instead of genuine Notepad++ installers. The vulnerability stemmed from inadequate validation of the integrity and authenticity of downloaded update files, making it possible for attackers to exploit classic man-in-the-middle techniques and supply-chain attack vectors.
In response, Notepad++ developers released an urgent update (v8.8.9) that strengthens the verification process for downloaded installers, now requiring strict digital signature and certificate checks before execution. If these checks fail, the update process is aborted to prevent the execution of untrusted code. The developer acknowledged that the investigation into the exact hijacking method is ongoing, but emphasized that the new security enhancements significantly reduce the risk of similar attacks. Users are advised to manually update to the latest version to ensure protection against this threat.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
After the fixes were released, reporting said the precise mechanism used to redirect or intercept update traffic remained under investigation, with ISP-level interception among the suspected possibilities. Users were advised to download updates only from the official Notepad++ site and watch for indicators such as gup.exe contacting unauthorized domains or spawning unusual processes.
Notepad++ released version 8.8.9 to fix the updater weakness by enforcing stricter digital-signature and certificate verification for installers. The project also advised users to upgrade immediately and remove any previously installed custom Notepad++ root certificates.
Public reporting revealed that the WinGUp updater did not adequately verify the integrity and authenticity of downloaded update files, allowing man-in-the-middle or traffic-hijacking attacks to replace legitimate updates with malware. Reports also noted risks tied to weak file authentication and use of a self-signed root certificate.
As an initial mitigation, the Notepad++ developer changed the update process in version 8.8.8 so updates would be downloaded only from GitHub, reducing opportunities for traffic interception and malicious file substitution. This was described as an early response while the full issue was still under investigation.
The issue first came to light when a user observed the WinGUp updater spawning a suspicious executable that conducted reconnaissance and exfiltrated system information instead of performing a normal update. This report helped identify that the update mechanism was being abused in the wild.
At least three organizations with interests in East Asia, including telecom and finance targets, were reportedly compromised after attackers hijacked the Notepad++ update process to deliver malicious executables. Security reporting linked the activity to highly targeted intrusions, with some evidence suggesting Chinese threat actors.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcecybersecuritynews.com
Open sourcesecurityonline.info
Open sourcebleepingcomputer.com
Open sourceheise.de
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.