Users of the text and code editor Notepad++ may have unknowingly downloaded a malicious update for the app after its shared hosting servers were hijacked last year. On Monday, the appâs developer, Don Ho, posted an update on the attack with more details, including that the hackers were âlikely a Chinese state-sponsored groupâ and that the appâs servers were vulnerable for roughly six months from June through December 2nd, 2025.
The post explains that the hijacking occurred on the appâs unnamed, now-former hosting providerâs end, stating that âTraffic from certain targeted users was selectively redirected to attacker-controlled served malicious update manifests.â When victims were redirected, their app update could be replaced with a malicious executable that, according to independent cybersecurity expert Kevin Beaumont, may have given the hackers remote access to a victimâs keyboard.
Don Hoâs post also adds that the attack involved âhighly selective targetingâ in terms of the victims it redirected away from the legitimate Notepad++ website. Kevin Beaumont noted that the victims he spoke with âare [organizations] with interests in East Asia.â So, while this is a serious security vulnerability, itâs possible that the hackers were busy watching specific people instead of just anyone.
The developer did not specify when they became aware of the attack, but said that âall attacker access was definitively terminatedâ by December 2nd. The Notepad++ updater has been updated itself with stronger security measures to check for tampering and verify that updates are legitimate.
Notepad++ users should make sure they are on at least version 8.8.9, which addressed the vulnerabilities from the hijacking attack, and they should probably download that version directly from the Notepad++ website. Additionally, Kevin Beaumont suggested users double-check that theyâre not using an unofficial version of Notepad++, keep a close eye on activity from âgup.exe,â the appâs updater, and check for a suspicious âupdate.exeâ or âAutoUpdater.exeâ file in their TEMP folder.
Notably, Don Ho, the developer of Notepad++, criticized the Chinese government in a 2019 app update. He called that version the âFree Uyghurâ edition, and told The Verge at the time that his website had faced DDoS attacks in response.
Read the full article here