Notepad++ confirmed that its website and update distribution path were compromised, enabling a supply-chain attack that delivered malicious payloads to some users. Reporting and follow-on analysis tied the activity to infrastructure associated with the Chinese espionage group Lotus Blossom, with researchers describing a campaign that abused trusted software delivery to gain initial access and establish persistence on victim systems.
Censys and other researchers mapped malicious network infrastructure used in the operation, while incident-response guidance and public triage tooling were released to help defenders identify affected hosts and hunt for indicators of compromise. Analysis from multiple firms said the intrusion appears to have run for months in 2025, raising concern that organizations using Notepad++ should review update activity, inspect outbound connections to known attacker infrastructure, and validate whether developer or hosting environments were tampered with.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
On February 10, 2026, LevelBlue released a technical analysis of the Notepad++ supply-chain compromise. The write-up further documented the incident and its mechanics for defenders and incident responders.
On February 4, 2026, a GitHub repository published a PowerShell triage script to help defenders detect indicators of compromise related to the Notepad++ supply-chain attack. The tool explicitly referenced Lotus Blossom and the June-November 2025 campaign window.
On February 3, 2026, Censys released research detailing the network infrastructure associated with the malicious Notepad++ activity. The publication added technical visibility into the infrastructure supporting the campaign.
Security reporting on February 2, 2026 attributed the Notepad++ hijacking and supply-chain activity to the Chinese Lotus Blossom threat group. This attribution became a key development in understanding the incident.
On February 2, 2026, public reporting and social media posts stated that Notepad++ had confirmed the compromise affecting its software distribution. This was the first clear public acknowledgment reflected in the provided references.
The known period of malicious Notepad++ distribution concluded in November 2025, ending the campaign window described by later researchers. This marks the latest inferred date for users receiving trojanized installers from the compromised infrastructure.
Between June and November 2025, trojanized Notepad++ downloads were served to victims, constituting a supply-chain attack. Reporting and later triage guidance tie this activity to Lotus Blossom and indicate users who downloaded during this window may have been exposed.
Threat actors linked to Lotus Blossom compromised infrastructure used to distribute Notepad++ software, turning the project’s hosting environment into a malicious delivery channel. Multiple later analyses describe this as the root cause of the supply-chain incident.
6 references tracked. Mallory keeps watching after this page renders.
levelblue.com
Open sourcegithub.com
Open sourcecensys.com
Open sourceforrester.com
Open sourcecyberplace.social
Open sourcetheregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.