Notepad++ hacked
#4
My team just finished handling this incident where I work. The Rapid7 report has great detail about IoCs. https://www.rapid7.com/blog/post/tr-chry...s-toolkit/

In a nutshell, it wasn't the CODE of Notepad++ that was compromised, it was the update infrastructure, managed by a hosting provider. Still a supply chain issue, but a subtle difference from something like the Solarwinds incident where actual application code was infected.

Infections only happened when you used the update feature within Notepad++ during the period of compromise of the hosting provider. Don Hon (the programmer) has indicated that they have switched to another hosting provider and improved the security of the update process using signed resources. https://notepad-plus-plus.org/news/hijac...fo-update/
Reply


Messages In This Thread
Notepad++ hacked - by Stanley Durham - 03.02.2026, 02:36
RE: Notepad++ hacked - by Stanley Durham - 03.02.2026, 18:23
RE: Notepad++ hacked - by Dale Yarker - 04.02.2026, 12:12
RE: Notepad++ hacked - by George Bleck - 05.02.2026, 14:41
RE: Notepad++ hacked - by Stanley Durham - 05.02.2026, 18:03

Forum Jump:


Users browsing this thread: 1 Guest(s)