Notepad++ hit by suspected Chinese state-sponsored hackers – here’s what we know so far


  • Notepad++ targeted in sophisticated supply-chain attack via compromised hosting server
  • Attackers delivered tainted updates to select victims by exploiting weak update verification controls
  • The breach lasted from June to December 2025, likely linked to Chinese state-sponsored actors, leading to migration to new hosting and tightened update verification

Notepad++ has confirmed that it was the victim of a highly targeted and sophisticated cyber attack, most likely carried out by a Chinese state-sponsored threat actor.

In a security notice published on the project’s website, the company explained that attackers managed to compromise the shared hosting provider’s server and used it to deliver tainted updates to a handful of carefully selected victims.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top