Notepad++ Hijacked by State-Sponsored Hackers

Latest Atari related news.
User avatar
exxos
Site Admin
Site Admin
Posts: 28344
Joined: 16 Aug 2017 23:19
Location: UK

Notepad++ Hijacked by State-Sponsored Hackers

Post by exxos »

Just saw this... As I use it.. others here might also..

https://notepad-plus-plus.org/news/hija ... fo-update/

According to the former hosting provider, the shared hosting server was compromised until September 2, 2025. Even after losing server access, attackers maintained credentials to internal services until December 2, 2025, which allowed them to continue redirecting Notepad++ update traffic to malicious servers. The attackers specifically targeted Notepad++ domain with the goal of exploiting insufficient update verification controls that existed in older versions of Notepad++. All remediation and security hardening were completed by the provider by December 2, 2025, successfully blocking further attacker activity.
User avatar
alexh
Site sponsor
Site sponsor
Posts: 1335
Joined: 17 Oct 2017 16:51
Location: Oxfordshire

Re: Notepad++ Hijacked by State-Sponsored Hackers

Post by alexh »

Yes I saw it yesterday. I had updated during the period the update server had been hijacked (Nov 2025) but I didn't experience any Malware.
Senior Principal ASIC Engineer - SystemVerilog, VHDL
Thalion Webshrine - http://thalion.atari.org
ST,STf,STfm,STe,MegaST,MegaSTe,Falcon060
A500+,A600,A4000/060,CD32,CDTV
User avatar
rubber_jonnie
Site Admin
Site Admin
Posts: 14888
Joined: 17 Aug 2017 19:40
Location: Essex

Re: Notepad++ Hijacked by State-Sponsored Hackers

Post by rubber_jonnie »

I saw this too and I'm a long time user of Notepad++, though these days I'm on Mac which isn't supported, but I do use it at work and on my workbench Windows machine.

Work however is tightly controlled so we don't just get updates.

I'mm be a little circumspect when I go to update my own machines though.
Collector of many retro things!
800XL and 65XE both with Ultimate1MB,VBXL/XE & PokeyMax, SIDE3, SDrive Max, 2x 1010 cassette, 2x 1050 one with Happy mod, 3x 2600 Jr, 7800 and Lynx II
Approx 20 STs, including a 520 STM, 520 STFMs, 3x Mega ST, MSTE & 2x 32 Mhz boosted STEs
Plus the rest, totalling around 50 machines including a QL, 3x BBC Model B, Electron, Spectrums, ZX81 etc...
peters
Posts: 224
Joined: 25 Feb 2023 20:44

Re: Notepad++ Hijacked by State-Sponsored Hackers

Post by peters »

Thanks. I use it at work too. I've passed the info around my team.
User avatar
mrbombermillzy
Moderator
Moderator
Posts: 2284
Joined: 03 Jun 2018 19:37

Re: Notepad++ Hijacked by State-Sponsored Hackers

Post by mrbombermillzy »

Luckily Ive moved from M$ over to Linux, so use the unaffected (and less politically charged it seems!) equivalent notepadqq:

https://notepadqq.com/s/

Return to “NEWS & ANNOUNCEMENTS”

Who is online

Users browsing this forum: ClaudeBot and 6 guests