• About Us
King of Computer Media
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
King of Computer Media
No Result
View All Result

Home - Latest Technology News - The well-known open source software Notepad++ was hijacked by Chinese state-level hackers for six months: comparable in scale to the SolarWinds incident

The well-known open source software Notepad++ was hijacked by Chinese state-level hackers for six months: comparable in scale to the SolarWinds incident

KOCPC Editor by KOCPC Editor
February 5, 2026 - Updated on August 4, 2026
in Latest Technology News

The world’s most popularOpen sourceOne of the text editors Notepad++, its official update mechanism was criticized by suspected Chinese state-levelhackerThe organization held hostages for six months. Attackers compromised the hosting provider’s infrastructure and redirected update traffic for specific users to malicious servers, allowing victims to unknowingly download installers with built-in backdoors. Notepad++ Developer Don Ho Posted on February 2statement, “deeply apologized” to all affected users, and revealed the full picture of the supply chain attack that continued from June to December 2025.

Notepad++ was hijacked by Chinese state-level hackers for six months

Unlike common software vulnerability attacks, this intrusion did not target the Notepad++ code itself, but started at the hosting provider’s shared server level. The technical process of the attack is as follows:

Phase 1: Compromising hosted servers (June to September 2, 2025)

The attacker successfully penetrated the shared hosting server where the Notepad++ official website is located and gained complete control. During this time, they were able to directly intercept and tamper with update traffic directed to `notepad-plus-plus.org`.

Phase 2: Maintain access certificates (September 2nd to December 2nd)

On September 2, 2025, the host performed a routine core and firmware update, which resulted in the attacker losing direct access to the server. However, they still had the login credentials for the server’s internal services and continued to use these credentials to redirect Notepad++ update traffic to the malicious server until all credentials were rotated on December 2. This is not a massive indiscriminate attack. The attacker adopts a “highly selective locking” strategy: only traffic from specific target users will be redirected, and other users will not be affected at all.

Validate defects with updates

Notepad++ uses a proprietary update tool called WinGUP (GUP). The tool will report the current version to `notepad-plus-plus.org/update/getDownloadUrl.php` and then obtain the update download URL from the returned XML file. The attacker took advantage of the shortcomings in the update verification of the old version of Notepad++ – the update traffic of the early version even only used HTTP transmission, and the downloaded files used self-signed root certificates, causing the attacker toCan intercept and tamper with traffic at the ISP level 。

The man behind the scenes: Chinese state-level hacker organization Lotus Blossom

Multiple independent security researchers have determined that the operator behind this attack is most likely a Chinese state-level hacker organization. Security firm Rapid7 further attributed the attack to Lotus Blossom (aka Violet Typhoon/APT31), a group known to have a long history of espionageServing the Chinese Government . The Hacker NewsreportAPT31 connection was also confirmed. The attack targets include government agencies, telecommunications industry, aviation industry, critical infrastructure and media industry, and the victim organizations all have business relationships with East Asia.

Rapid7 named the malicious payload planted by the attacker Chrysalis and described it as “a feature-rich customized backdoor.” Rapid7 researchers said: “The breadth of its capabilities indicates that this is a sophisticated and persistent tool rather than a simple one-time malware.” This means that through Chrysalis, an attacker can gain complete remote control of the victim device, performing so-called “hands-on keyboard” operations: the attacker directly controls the infected computer through a web interface.

Independent security researcher Kevin Beaumont revealed that at least three organizations reported to him that security incidents occurred on devices with Notepad++ installed on their networks, and attackers successfully obtained direct control at the keyboard level.

Supply chain attack comparable to SolarWinds

In its report, TechCrunch compared this incident to the 2019-2020 SolarWinds Supply Chain AttackComparable. In the SolarWinds incident, Russian state-level hackers invaded the company’s servers and secretly implanted backdoors in its IT management software, affecting multiple government agencies including the U.S. Departments of Homeland Security, Commerce, Energy, Justice, and State. Although the scale of the Notepad++ incident appears to be small at present (because it is a highly selective attack), the sophistication of the attack method and the duration (six months) are equally alarming.

Fixes

After the incident was exposed, the Notepad++ team took the following measures:

1. Migrate to a new hosting provider: Choose a provider with stronger security practices
2. Enhanced update tool WinGUP: Added two-factor verification of certificate and signature for downloading and installing programs in v8.8.9
3. XML signature verification: Update the XML file returned by the server to include the XMLDSig digital signature.
4. Mandatory verification: Certificate and signature verification will be fully enforced in v8.9.2

Don Ho appealsAll users to manually download v8.9.1 or newer now, and execute the installer to update.

Follow-up investigations continue

After the incident became public, many security companies successively released more detailed technical analysis:

– Rapid7 released a complete analysis report of the Chrysalis backdoor 
– Kaspersky released compromise indicators on February 3
– Original host provided additional IoC information on February 5

It is worth noting that Don Ho admitted in his initial statement that his incident response team spent a week analyzing about 400 GB of server logs. Although traces of intrusion were found, they were unable to find specific indicators of intrusion (such as binary hash values, malicious domains or IP addresses). It was not until Rapid7 and Kaspersky intervened that more traceable information was obtained.

Advice to users

General users:
– Immediately from [Official website] Manually download v8.9.1 or newer version
– Be aware that search engines are flooded with disguised Notepad++ malvertising

Enterprise users:
– Consider blocking `notepad-plus-plus.org` or preventing `gup.exe` from connecting to the Internet
– Can further block network access rights of `notepad++.exe` (unless there is a complete extension monitoring mechanism)
– Refer to the IoC issued by Rapid7 for internal investigation

Source: KOCPC Chinese

Tags: hackerInformation securityNotepadOpen source

Recent Posts

  • The Xiaomi Pad 8S Pro has passed network access certification and will debut with the self-developed XRING O3 chip.
  • The entire Google Pixel 11 lineup has been leaked! Official promotional renders of the Pixel 11 Pro XL have also surfaced
  • Are Chinese phone battery capacities falsely labeled? A brief look at the “capacity locking” phenomenon in Chinese silicon-carbon batteries.
  • NCC is leaderless, recklessly sending out national-level alert messages!?
  • What does “QR” in QR Code mean?

Recent Comments

No comments to show.
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology

No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology