Notepad++ Update Service Compromised by State-Sponsored Attack

Notepad++ Update Service Compromised by State-Sponsored Attack

First seen 2 Feb 2026, 19:29 UTC Heise.DeTheregisterBleepingcomputerCsoonline 30.6

Article Content

Browse articles
ThreatCluster

In 2025, Notepad++'s update service was compromised by a state-sponsored cyber criminal, leading to the injection of malware into the software. The incident prompted the release of version 8.8.9 on December 9, which included a hardened update process that verified the signature and certificate of installers. Subsequently, version 8.9 was released on December 27, eliminating the use of a self-signed certificate and ensuring only a legitimate certificate from GlobalSign is used.