Skip to content
Notepad++ Update Service Compromised by State-Sponsored Attack

Notepad++ Update Service Compromised by State-Sponsored Attack

First seen 2 Feb 2026, 19:29 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

In 2025, Notepad++'s update service was compromised by a state-sponsored cyber criminal, leading to the injection of malware into the software. The incident prompted the release of version 8.8.9 on December 9, which included a hardened update process that verified the signature and certificate of installers. Subsequently, version 8.9 was released on December 27, eliminating the use of a self-signed certificate and ensuring only a legitimate certificate from GlobalSign is used.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 213d ago How this analysis works

More articles in this cluster (7)