Threat actors compromised Notepad++ update infrastructure at the hosting-provider level and used it to redirect download/update traffic to attacker-controlled servers, enabling distribution of malicious updates to selected targets. Reporting described a multi-month intrusion window (mid-2025 through late 2025) in which attackers initially gained access to the shared hosting environment, then—after losing direct server access following maintenance—continued operating by leveraging retained valid credentials for internal services to keep redirecting requests from https://notepad-plus-plus.org/getDownloadUrl.php to malicious infrastructure.
Technical reporting described three distinct infection chains observed during the operation, with targeting across government, financial, and IT sectors in multiple countries (including Vietnam, El Salvador, Australia, and the Philippines). The activity included abuse of legitimate software (e.g., ProShow), malicious Lua scripts, and deployment of the Chrysalis backdoor; CERT-EU’s February 2026 cyber brief also highlighted the incident as a Notepad++ supply-chain compromise attributed in open reporting to the China-linked group Lotus Blossom.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
In its February 2026 cyber brief published on 2026-03-02, CERT-EU highlighted the Notepad++ supply-chain compromise and attributed it to the China-linked Lotus Blossom campaign, adding broader threat-intelligence context to the incident.
On 2025-12-09, Notepad++ released version 8.8.9, hardening the WinGUp updater to verify installer signatures and certificates to reduce the risk of similar supply-chain abuse.
On 2025-12-02, the malicious redirection activity was remediated, ending the attackers' ability to route Notepad++ updater traffic to attacker-controlled infrastructure.
During the compromise, victims attempting to update Notepad++ received a malicious NSIS installer named update.exe that performed reconnaissance and data exfiltration, then launched one of several infection chains including Cobalt Strike Beacon delivery and deployment of the Chrysalis backdoor.
On 2025-09-02, the attackers reportedly lost direct access to the shared hosting server but retained valid internal-service credentials, allowing them to continue redirecting requests from notepad-plus-plus.org to attacker-controlled servers.
Between June and December 2025, attackers compromised Notepad++'s update infrastructure through a hosting-provider-level breach, enabling them to tamper with updater traffic and serve malicious downloads to users seeking updates.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.