Notepad++ released v8.9.2 to harden its update process after a state-linked intrusion enabled attackers to hijack update traffic and selectively deliver malware to targeted users. The new “double-lock” design adds cryptographic verification of the signed XML update metadata returned by notepad-plus-plus[.]org (via XMLDSig) and complements earlier protections (introduced in v8.8.9+) that verify the signed installer downloaded from GitHub. Additional security changes to the WinGUp auto-updater include removing libcurl.dll to reduce DLL side-loading risk, removing insecure cURL SSL options (CURLSSLOPT_ALLOW_BEAST, CURLSSLOPT_NO_REVOKE), and restricting plugin-management execution to binaries signed with the same certificate as WinGUp.
Reporting attributes the compromise to a China-linked actor (including Lotus Blossom) that abused a shared hosting provider-level breach to intercept and redirect update requests between June and December 2025, with selective victim targeting spanning government, telecom, and critical infrastructure—primarily in Southeast Asia but also affecting other regions. The campaign leveraged weaknesses in older WinGUp verification to deliver a malicious NSIS installer (update.exe) and execute follow-on payloads; described chains include a Lua script injection path delivering Cobalt Strike and another using DLL sideloading (including abuse of a legitimate Bitdefender component BluetoothService.exe to load a malicious log.dll) to deploy the Chrysalis backdoor. Notepad++ also fixed CVE-2026-25926 (CVSS 7.3), an unsafe search path issue that could allow arbitrary code execution by launching Windows Explorer without an absolute path, potentially enabling execution of a malicious explorer.exe if the working directory is attacker-controlled.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
Version 8.9.2 also patched CVE-2026-25926, a high-severity unsafe search path issue that could allow arbitrary code execution through abuse of how Windows Explorer is launched. This fix was included alongside the update-channel hardening.
On February 16, 2026, Notepad++ released version 8.9.2, adding XML digital signature verification for update metadata and combining it with signed installer validation. The release also hardened WinGUp by removing libcurl.dll, tightening TLS/SSL behavior, and restricting plugin-related execution to signed components.
In response to the compromise, Notepad++ released version 8.9.1 with stronger installer and update-response verification and moved to a new hosting provider. The project also announced plans for stricter update validation in the next release.
Security researchers including Rapid7, Kaspersky, and Palo Alto Networks linked the hijacked-update campaign to the China-linked espionage group Lotus Blossom, also referred to in some reporting as Lotus Panda. Their analysis tied the operation to the Chrysalis malware and the compromised update chain.
Notepad++'s disclosure said the hosting-provider-level breach and malicious redirection activity were detected in early December 2025. Reporting places the campaign's end around late 2025, with some sources citing November 10 and others December 2.
The selective update hijacking primarily affected targets in Southeast Asia, with additional victims later identified in South America, the United States, and Europe. The operation was described as targeted rather than mass exploitation.
During the campaign, tampered Notepad++ updates delivered multi-stage malware including Cobalt Strike Beacon and a previously undocumented backdoor called Chrysalis. One infection path used a malicious NSIS installer and DLL sideloading through a legitimate Bitdefender binary.
Notepad++ further strengthened update security in version 8.8.9 by verifying installer signatures and certificates. This reduced the risk of malicious binaries being accepted through the update process.
Before the final 2026 fixes, Notepad++ began hardening its updater in version 8.8.8 by addressing the previously unsigned XML update descriptor. This was an early step in securing the update channel after weaknesses were identified.
Beginning in June 2025, attackers compromised infrastructure at Notepad++'s hosting provider and started intercepting WinGUp update requests. They selectively redirected targeted users to attacker-controlled infrastructure serving malicious update content.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
trustedsec.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourcego.theregister.com
Open sourcehelpnetsecurity.com
Open sourcecsoonline.com
Open sourcecybersecuritynews.com
Open sourcenotepad-plus-plus.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.