• Send Us A Tip
  • Calling all Tech Writers
  • Advertise
Sunday, June 21, 2026
  • Login
TechStory
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to
No Result
View All Result
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to
No Result
View All Result
TechStory
No Result
View All Result
Home Tech

Notepad++ Compromised in Sophisticated Nation-State Attack

by Sneha Singh
February 3, 2026
in Tech
Reading Time: 5 mins read
0
Notepad++ Compromised in Sophisticated Nation-State Attack
TwitterWhatsappLinkedin

Notepad++, a popular text editor, has come forward about a sophisticated supply chain attack that took place on its update system for about six months, from June to December 2025. This is a serious security breach that has happened to widely used open-source software in a while.

You might also like

How to Increase Gas Mileage: Small Driving Changes That Save Big at the Pump

Paradigms of Luminance and Chemistry The Definitive OLED vs Mini LED Display Audit

Next-Generation Wireless The Architectural Breakthrough of Wi-Fi 7 Explained

This was not just a website hack or a vulnerability in the code. It has been found that the attackers were able to compromise Notepad++’s shared hosting provider at an infrastructure level. This helped them to intercept and redirect the update traffic only meant for notepad-plus-plus.org to the attacker-controlled servers, which then provided the malicious update manifest in place of the actual software update.

What is particularly worrisome about this attack is that it was carried out with such precision. Instead of compromising all users, the attackers chose to target certain individuals. 

Several independent security researchers have determined that the threat actor is likely to be a Chinese state-sponsored actor, which would account for the level of selectivity seen in this attack. The hosting provider has verified that the bad actors specifically searched for the Notepad++ domain with the intent of exploiting the lack of update verification controls that were present in older versions of the software.

How the Notepad++ Attack Unfolded

Analysis of the timeline of the compromise shows a complex and multi-step attack. The shared hosting server was compromised at some point around June 2025. 

Notably, a maintenance update on September 2, 2025, which covered kernel and firmware updates, seems to have removed the attackers from the server. 

However, they had already gained access to the credentials of the internal services, enabling them to retain their capacity to redirect traffic to the malicious servers until December 2, 2025.

This meant that the attackers, who had lost access to the server, could continue their activities for the next three months. They retained their capacity to intercept traffic destined for the Notepad++ update URL and redirect it to the attacker-controlled infrastructure that hosted the compromised software packages.

Notepad++ Compromised in Sophisticated Nation-State Attack
Credits: LinkedIn

The investigation by the hosting service showed that no other client was affected on the same shared hosting server, which emphasizes the targeted nature of the attack on Notepad++. The attackers were observed to have attempted to re-exploit vulnerabilities even after patches were applied, although these attempts failed.

The Response and Remediation

After the breach was identified and understood, rapid remediation efforts were initiated on various fronts. The hosting company has since rotated all credentials that may have been affected and applied patches to ensure that such breaches are not repeated in the future. All security remediation and hardening efforts were completed by December 2, 2025, and were successful in mitigating any further malicious activity.

In addition to the remediation efforts initiated by the hosting company, major changes have been initiated within the Notepad++ application. The update component of the Notepad++ application, WinGup, has received major security updates in version 8.8.9. These updates include the verification of both the certificate and the signature of downloaded installers. Furthermore, the XML data received from the update server is now digitally signed using XMLDSig, with certificate and signature verification to be enforced starting with the upcoming version 8.9.2.

Notepad++ has since moved its website to a new hosting company with much-improved security practices, abandoning the shared hosting environment that was compromised.

Results of Incident Response and Required Actions for Notepad++ Infrastructure

Dear Customer,

We want to further update you following the previous communication with us about your server compromise and further investigation with your incident response team.

We discovered the suspicious events in our logs, which indicate that the server (where your application https://notepad-plus-plus.org/update/getDownloadUrl.php was hosted until the 1st of December, 2025) could have been compromised.

As a precautionary measure, we immediately transferred all clients’ web hosting subscriptions from this server to a new server and continued our further investigation.

Here are the key finding points:

  1. The shared hosting server in question was compromised until the 2nd of September, 2025. On this particular date, the server had scheduled maintenance where the kernel and firmware were updated. After this date, we could not identify any similar patterns in logs, and this indicates that bad actors have lost access to the server. We also find no evidence of similar patterns on any other shared hosting servers.
  2. Even though the bad actors have lost access to the server from the 2nd of September, 2025, they maintained the credentials of our internal services existing on that server until the 2nd of December, which could have allowed the malicious actors to redirect some of the traffic going to https://notepad-plus-plus.org/getDownloadUrl.php to their own servers and return the updates download URL with compromised updates.
  3. Based on our logs, we see no other clients hosted on this particular server being targeted. The bad actors specifically searched for https://notepad-plus-plus.org/ domain with the goal to intercept the traffic to your website, as they might know the then-existing Notepad++ vulnerabilities related to insufficient update verification controls.
  4. After concluding our research, the investigated security findings were no longer observed in the web hosting systems from the 2nd of December, 2025, and onwards, as:

We have fixed vulnerabilities, which could have been used to target Notepad++. In particular, we do have logs indicating that the bad actor tried to re-exploit one of the fixed vulnerabilities; however, the attempt did not succeed after the fix was implemented.

We have rotated all the credentials that bad actors could have obtained until the 2nd of September, 2025.

We have checked the logs for similar patterns in all web hosting servers and couldn’t find any evidence of systems being compromised, exploited in a similar way, or data breached.

While we have rotated all the secrets on our end, below you will find the preventive actions you should take to maximize your security. However, if the following actions have been done after the 2nd of December, 2025, no actions are needed from your side.

Change credentials for SSH, FTP/SFTP, and MySQL database.

Review administrator accounts for your WordPress sites (if you have any), change their passwords, and remove unnecessary users.

Update your WordPress sites (if you have any) plugins, themes, and core version, and turn on automatic updates, if applicable.

We appreciate your cooperation and understanding. Please let us know if you have any questions.

What Users Should Do

This incident is a sobering reminder of the level of threats that open-source software projects are now facing and the need for high-quality security practices to be in place throughout the entire software supply chain, from code development through to hosting infrastructure and software update mechanisms.

Tags: Nation-State AttackNotedpad++XML data
Tweet63SendShare18
Previous Post

32-Year-Old Chinese Programmer, Gao Added to Work Group While Hospitalized Prior to Death

Next Post

Optimizing Your Tech Arsenal with the Right Credit Card Strategy

Sneha Singh

Sneha is a skilled writer with a passion for uncovering the latest stories and breaking news. She has written for a variety of publications, covering topics ranging from politics and business to entertainment and sports.

Recommended For You

How to Increase Gas Mileage: Small Driving Changes That Save Big at the Pump

by Samir Gautam
June 21, 2026
0
Fuel prices may rise and fall, but one thing stays constant: drivers want to make every litre go further. The good news is that improving gas mileage does not always require buying a new hybrid or changing cars altogether. A few disciplined habits behind the wheel, along with basic maintenance, can make a noticeable difference over time. For most drivers, the biggest gains come from reducing waste. That means less aggressive acceleration, fewer unnecessary trips, correctly inflated tyres and a car that is mechanically healthy. Smooth Driving Uses Less Fuel The quickest way to burn more fuel is to drive as if every traffic light is a starting grid. Hard acceleration, sharp braking and sudden changes in speed force the engine to work harder and consume more petrol. A smoother approach works better. Accelerate gradually, maintain a steady speed where possible and look ahead to anticipate traffic. If a red light is visible in the distance, easing off the accelerator early is usually more efficient than rushing forward and braking hard at the last moment. Speed also matters. As speeds rise, aerodynamic drag increases and the engine needs more energy to keep the vehicle moving. On highways, staying within a sensible cruising range rather than constantly pushing at high speeds can help reduce fuel consumption. Check Tyre Pressure Regularly Tyres are easy to ignore until something goes wrong, but they play a major role in fuel economy. Under-inflated tyres create more rolling resistance, which means the engine has to use more fuel just to move the car forward. Drivers should check tyre pressure at least once a month, preferably when the tyres are cold. The correct pressure is usually listed on the driver-side door frame or in the owner’s manual. It is important not to use the maximum pressure printed on the tyre sidewall as a target. That figure is not necessarily the recommended setting for the vehicle. The US Environmental Protection Agency notes that under-inflation reduces fuel economy, increases tyre wear and adds to emissions. Stop Carrying Extra Weight A car is not a storage room. Heavy items in the boot may seem harmless, but extra weight makes the engine work harder, especially in city traffic where the vehicle is constantly stopping and starting. Clear out unnecessary tools, boxes, sports gear and other items that have been sitting in the car for weeks. Roof racks and cargo boxes can also hurt mileage by increasing aerodynamic drag. If they are not being used, remove them. This is especially relevant for drivers who spend most of their time on highways, where wind resistance becomes a bigger factor. Keep Up With Maintenance A well-maintained vehicle is usually a more fuel-efficient vehicle. Delayed oil changes, worn spark plugs, clogged air filters, dragging brakes and poor wheel alignment can all affect how efficiently a car runs. Following the manufacturer’s service schedule is the safest route. Use the recommended engine oil grade and get warning lights checked instead of ignoring them. A sudden drop in mileage can be an early sign that something needs attention. The EPA advises motorists to follow their vehicle maintenance schedule and use the recommended motor oil to support better fuel efficiency and safer operation. Combine Trips and Avoid Long Idling Short trips can be surprisingly fuel-hungry because the engine has not had enough time to reach its most efficient operating temperature. Combining errands into one planned route can reduce cold starts, unnecessary kilometres and fuel use. Idling is another quiet fuel drain. If you are waiting for an extended period, switching off the engine can be more sensible than leaving it running. Modern cars do not need long warm-up periods before driving. Start, settle for a few seconds and drive gently. The Bottom Line Better gas mileage is less about one miracle trick and more about consistent habits. Drive smoothly, maintain the right tyre pressure, remove excess weight and service the car on time. These small changes may not feel dramatic on a single trip, but over months of commuting, school runs and highway drives, they can add up to real savings.

Fuel prices may rise and fall, but one thing stays constant: drivers want to make every litre go further. The good news is that improving gas mileage does...

Read more

Paradigms of Luminance and Chemistry The Definitive OLED vs Mini LED Display Audit

by Anochie Esther
June 21, 2026
0
OLED vs Mini LED

The global display and consumer electronics sectors are locked in a historic technological civil war. For years, the gold standard of premium visual performance was dictated by a...

Read more

Next-Generation Wireless The Architectural Breakthrough of Wi-Fi 7 Explained

by Anochie Esther
June 21, 2026
0
Wi-Fi 7 Explained

The global networking landscape is entering a period of massive data scaling. For years, consumer and enterprise spaces managed their growing hardware ecosystems by relying on iterative upgrades...

Read more
Next Post
Photo by Avery Evans on Unsplash

Optimizing Your Tech Arsenal with the Right Credit Card Strategy

Please login to join discussion

Techstory

Tech and Business News from around the world. Follow along for latest in the world of Tech, AI, Crypto, EVs, Business Personalities and more.
reach us at info@techstory.in

Advertise With Us

Reach out at - info@techstory.in

Aviator Game India 2026

BROWSE BY TAG

#Crypto #howto 2024 acquisition AI amazon Apple Artificial Intelligence bitcoin Business China cryptocurrency e-commerce electric vehicles Elon Musk Ethereum facebook funding Gaming Google India Instagram Investment ios iPhone IPO Market Markets Meta Microsoft News OpenAI samsung Social Media SpaceX startup startups tech technology Tesla TikTok trend trending twitter US

© 2025 Techstory.in

No Result
View All Result
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to

© 2025 Techstory.in

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?