Notepad++ Compromised By State Actor (notepad-plus-plus.org)
(Tuesday February 03, 2026 @11:00AM (msmash)
from the security-woes dept.)
[1]Luthair writes:
> Notepad++ claims to have been targeted by a state actor, given their previous stance on Uyghurs one can speculate about a candidate.
Notepad++, [2]in a blog post :
> According to the analysis provided by the security experts, the attack involved infrastructure-level compromise that allowed malicious actors to intercept and redirect update traffic destined for notepad-plus-plus.org. The exact technical mechanism remains under investigation, though the compromise occurred at the hosting provider level rather than through vulnerabilities in Notepad++ code itself. Traffic from certain targeted users was selectively redirected to attacker-controlled served malicious update manifests.
[1] https://slashdot.org/~Luthair
[2] https://notepad-plus-plus.org/news/hijacked-incident-info-update/
> Notepad++ claims to have been targeted by a state actor, given their previous stance on Uyghurs one can speculate about a candidate.
Notepad++, [2]in a blog post :
> According to the analysis provided by the security experts, the attack involved infrastructure-level compromise that allowed malicious actors to intercept and redirect update traffic destined for notepad-plus-plus.org. The exact technical mechanism remains under investigation, though the compromise occurred at the hosting provider level rather than through vulnerabilities in Notepad++ code itself. Traffic from certain targeted users was selectively redirected to attacker-controlled served malicious update manifests.
[1] https://slashdot.org/~Luthair
[2] https://notepad-plus-plus.org/news/hijacked-incident-info-update/