Skip to main content

Share story

Security

Notepad++ confirms Chinese government hackers hijacked software updates for months

Notepad++ confirms Chinese government hackers hijacked software updates for months Image: Primary
The developer of Notepad++ has confirmed that hackers hijacked the software to deliver malicious updates to users over the course of several months in 2025. In a blog post published Monday, developer Don Ho said that the cyberattack was likely carried out by hackers associated with the Chinese government between June and December 2025. Ho cited multiple analyses by security experts who examined the malware payloads and attack patterns. Ho said this would explain the highly selective targeting seen during the campaign. Rapid7 attributed the hacking to Lotus Blossom, a long-running espionage group known to work for China, and said the hacks targeted government, telecom, aviation, critical infrastructure, and media sectors. Kevin Beaumont, a security researcher who first discovered the cyberattack, said the hackers compromised a small number of organizations with interests in East Asia after someone unwittingly used a tainted version of the software. Beaumont said the hackers were able to gain hands-on access to the computers of victims who were running hijacked versions of Notepad++. Ho said the exact technical mechanism of how the hackers broke into his servers remains under investigation. The attackers specifically targeted Notepad++'s web domain with the goal of exploiting a bug in the software to redirect some users to a malicious server. This allowed the hackers to deliver malicious updates to certain users until the bug was fixed in November and the hackers' access was terminated in early December. Ho said his hosting provider confirmed his shared server was compromised but did not say how the hackers initially broke in. Ho apologized for the incident and urged users to download the most recent version of his software, which contains a fix for the bug. Ho wrote that logs indicate the bad actor tried to re-exploit one of the fixed vulnerabilities, but the attempt did not succeed after the fix was implemented.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from TechCrunch and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Science
Science

Infleqtion claims 30 entangled logical qubits on Sqale system

Infleqtion says it created 30 entangled logical qubits on its Sqale quantum computing system, a company-reported step toward operations across error-protected quantum bits. A logical qubit encodes information across multiple physi...

Capital AI
Capital AI

NUS Enterprise launches patent-matching platform and Munich outpost

NUS Enterprise says it has launched Nova, an AI platform developed with Zima Labs to help its staff find commercial partners for university research. It has also established an outpost in Munich through a partnership with Unterneh...

Security
Security

NFM Lending faces lawsuit after acknowledged cyber incident

NFM Lending faces a class-action lawsuit after acknowledging a cybersecurity incident, The Tech Edvocate reports. Former customer Sheneka Smith alleges that the mortgage lender failed to maintain reasonable safeguards for customer...

Infrastructure Products
Infrastructure Products

Microsoft offers rollback for Windows desktop loading fault

Microsoft has confirmed that updates beginning with its August 2026 preview release can leave some users with a black screen after sign-in or cause Windows Explorer to crash. The problem mainly affects Azure Virtual Desktop hosts ...

Products Infrastructure
Products Infrastructure

DLSS 5 test finds higher power draw and connector heat on RTX 5090

Enabling Nvidia's DLSS 5 raised power draw through a GeForce RTX 5090 Founders Edition's 16-pin connector from 582.7W to 646.7W in tests by Korean outlet QuasarZone, Tom's Hardware reports. The connector reached 91.7 degrees Celsi...