The developer did not specify when they became aware of the attack, but said that “all attacker access was definitively ...
Rapid7 links China-linked Lotus Blossom to a 2025 Notepad++ hosting breach that delivered the Chrysalis backdoor via hijacked ...
State-sponsored threat actors compromised the popular code editor's hosting provider to redirect targeted users to malicious ...
Notepad++ is a favorite of programmers and other power users, but its auto-update function was compromised for months in 2025 ...
The attacks came from a third-party and not from the Notepad++ team.
A Chinese-linked cyberespionage group named Lotus Blossom hijacked the update process of Notepad++ to target specific users. Gaining access in June 2025, they maintained control until December that ...
The popular Notepad alternative was hijacked by bad actors for several months in 2025, but the latest update appears to solve the issue.