Notepad++ maintainers confirmed a months-long compromise of the project’s former shared hosting/update infrastructure that enabled a likely Chinese state-sponsored actor to selectively hijack update traffic and redirect targeted users to attacker-controlled servers hosting malicious payloads. The activity ran from June 2025 to early December 2025 and was characterized as highly selective rather than broad “spray and pray” distribution, indicating a well-resourced adversary focused on specific victims.
Investigations attributed the intrusion to an infrastructure-level takeover (compromise of the shared hosting environment) rather than a vulnerability in the Notepad++ codebase itself. The attacker-controlled redirection path included the updater’s getDownloadUrl.php endpoint and leveraged insufficient update verification in older updater/Notepad++ versions (prior to v8.8.9, including older WinGUp behavior) that did not strictly enforce certificate/signature validation for downloaded installers. Reporting also describes multiple phases of access during the incident window, with the hosting provider ultimately evicting the attacker by Dec 2, 2025.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
17 events from the most recent confirmed update back to the earliest known activity.
By early February 2026, reports stated that Notepad++ version 8.9.1 added XMLDSig validation for update metadata as another mitigation step. The project also said stricter enforcement of signed update metadata was planned for version 8.9.2.
On February 3, 2026, follow-on analysis mapped command-and-control and delivery infrastructure associated with the campaign, including domains such as api.skycloudcenter.com and api.cloudtrafficservice.com and likely related IPs. Researchers noted some related infrastructure remained active at the time of publication.
On February 3, 2026, Securelist/Kaspersky published a breakdown of three distinct infection chains observed from July to October 2025, including reconnaissance, temp.sh exfiltration, Metasploit downloaders, Cobalt Strike, and Chrysalis. The report also provided extensive indicators of compromise and hunting guidance.
By February 3, 2026, Rapid7 reported with moderate confidence that the campaign was linked to the China-linked espionage group Lotus Blossom and identified a previously undocumented backdoor called Chrysalis. The firm described a malicious NSIS installer, DLL sideloading via a renamed Bitdefender binary, and related post-compromise tooling.
Following the public disclosure on February 2, 2026, multiple researchers and outlets assessed the operation as likely tied to a Chinese state-sponsored espionage actor based on its selectivity, victimology, and tradecraft. Early public attributions included Violet Typhoon/APT31/Zirconium and other China-linked clusters.
On February 2, 2026, Notepad++ disclosed that its update infrastructure had been hijacked for months in 2025, selectively redirecting some users to malicious servers. The project said it had migrated to a new hosting provider and urged users to upgrade.
On December 27, 2025, Notepad++ released version 8.9, replacing use of a self-signed certificate with a legitimate GlobalSign-issued certificate. This was part of the broader effort to harden update trust and certificate handling.
In December 2025, researcher Kevin Beaumont publicly outlined his suspicion that weaknesses in the Notepad++ updater were being exploited in targeted intrusions involving hands-on-keyboard access at a small number of organizations with East Asia interests. Later disclosures indicated his hypothesis was correct.
On December 9, 2025, Notepad++ released version 8.8.9 to harden WinGUp by verifying installer digital signatures and matching certificates, aborting updates on failure. Don Ho also publicly tied the release to concerns about update-traffic hijacking.
On December 2, 2025, the hosting provider said it detected and terminated the remaining attacker access, including abuse of internal service credentials. This date is widely cited as the latest possible end of the compromise window.
Notepad++ released version 8.8.8 on November 18, 2025, adding initial hardening to the updater by restricting update sources and moving update delivery toward safer channels. Multiple reports cite this release as an early mitigation step before stronger verification was added.
Investigators assessed that active malicious redirection or exploitation had ended by November 10, 2025, although some reports note uncertainty because credential-based access may have remained available afterward. This date appears in several accounts as the likely operational end of the campaign.
After September 2, 2025, the attackers reportedly continued manipulating update traffic by using valid or stolen credentials for internal hosting-provider services. This allowed selective redirection to persist despite loss of direct server foothold.
On September 2, 2025, scheduled kernel and firmware updates at the hosting provider disrupted the attackers' direct access to the compromised shared server. However, this did not fully stop the campaign.
Telemetry later showed the campaign targeted a small set of victims from roughly July through October 2025, including organizations and individuals in Vietnam, the Philippines, El Salvador, and Australia. Affected sectors included government, financial services, telecommunications, aviation, critical infrastructure, and IT services.
Starting in June 2025, attackers began selectively redirecting some Notepad++ updater requests to attacker-controlled servers that served tampered update manifests and trojanized installers. The operation was highly targeted rather than a mass distribution campaign.
The former shared hosting environment used for Notepad++ update delivery was compromised around June 2025, giving attackers control over the getDownloadUrl.php update path. Reporting consistently describes this as an infrastructure-level breach rather than a compromise of Notepad++ source code or build systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
35 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcehelpnetsecurity.com
Open sourcevulnu.com
Open sourceschneier.com
Open sourcethehackernews.com
Open sourcesecurityonline.info
Open sourcecybersecuritynews.com
Open sourcedarkreading.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.