Notepad++ announced that its update infrastructure was compromised, possibly by a Chinese state entity, between June and December 2025. It said the breach occurred at its previous hosting provider and allowed update traffic to be redirected to malicious servers.
According to security analysts who investigated the situation, the attackers targeted a subset of users to deliver compromised updates. The targeted approach suggests an espionage campaign rather than a broad malware distribution effort.




