Notepad++ hacked what should I do

Notepad++ announced that its update infrastructure was compromised, possibly by a Chinese state entity, between June and December 2025. It said the breach occurred at its previous hosting provider and allowed update traffic to be redirected to malicious servers.

According to security analysts who investigated the situation, the attackers targeted a subset of users to deliver compromised updates. The targeted approach suggests an espionage campaign rather than a broad malware distribution effort.

See more articles from iGuRu.gr when you search for news on Google.

The breach began at the hosting provider level, where the attackers maintained access to the server until maintenance on September 2, 2025. Even after losing direct access to the server, the hackers retained internal service credentials until December 2, 2025, which allowed for continued traffic interception.

Hackers exploited the getDownloadUrl.php endpoint to provide URLs for compromised software versions. To address this issue, the hosting provider has rotated all internal credentials and the Notepad++ application has been migrated to a different, hardened server environment.

If you updated Notepad++ between June and December, you may have accidentally downloaded malicious files. The attackers exploited known vulnerabilities in older versions of the software, such as inadequate update verification checks.

In response to this incident, Notepad++ abandoned its previous shared hosting for a provider with better security protocols.

With the latest version of Notepad++ v8.8.9, there are preliminary security improvements in the WinGup application update. Based on this, Notepad++ will release version v8.9.2 in a month, which will strictly enforce the XMLDSig certificate and signature verification. This will ensure that the update server responses cannot be compromised or redirected by unauthorized users.

It is recommended that all users ensure they are running at least version 8.8.9 (Notepad++ v8.8.9: vulnerability-fix).

The latest version released is Notepad++ v8.9.1


Google preferences

Leave a Comment

Your email address will not be published. Required fields are marked *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).