


Perceptive Security
SOC/SIEM Consultancy

Supply-Chain Hijacking of Notepad++ Updates via Hosting Provider Compromise (Campaign)
Published:
2 februari 2026 om 00:00:00
Alert date:
2 februari 2026 om 14:01:37
Source:
threats.wiz.io
Supply Chain & Dependencies
Between June and late 2025, threat actors compromised the shared hosting infrastructure used by Notepad++ and selectively hijacked update traffic destined for notepad-plus-plus.org. The attackers did not exploit vulnerabilities in Notepad++ code itself, but rather abused access at the hosting provider level to intercept and manipulate software updates. This represents a sophisticated supply chain attack targeting a widely-used text editor application through its update mechanism. The campaign demonstrates how attackers can compromise software distribution channels without directly targeting the application vendor's infrastructure.
Technical details
Mitigation steps:
Affected products:
Notepad++
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
