{"id":895,"date":"2026-02-02T12:44:51","date_gmt":"2026-02-02T10:44:51","guid":{"rendered":"https:\/\/familiebuckens.nl\/?p=895"},"modified":"2026-02-02T12:46:20","modified_gmt":"2026-02-02T10:46:20","slug":"notepad-official-update-mechanism-hijacked-to-deliver-malware-to-select-users","status":"publish","type":"post","link":"https:\/\/familiebuckens.nl\/index.php\/2026\/02\/02\/notepad-official-update-mechanism-hijacked-to-deliver-malware-to-select-users\/","title":{"rendered":"Notepad++ Official Update Mechanism Hijacked to Deliver Malware to Select Users"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The maintainer of Notepad++ has revealed that state-sponsored attackers hijacked the utility&#8217;s update mechanism to redirect update traffic to malicious servers instead.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;The attack involved [an] infrastructure-level compromise that allowed malicious actors to intercept and redirect update traffic destined for notepad-plus-plus.org,&#8221; developer Don Ho&nbsp;<a href=\"https:\/\/notepad-plus-plus.org\/news\/hijacked-incident-info-update\/\" rel=\"noreferrer noopener\" target=\"_blank\">said<\/a>. &#8220;The compromise occurred at the hosting provider level rather than through vulnerabilities in Notepad++ code itself.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The exact mechanism through which this was realized is currently being investigated, Ho added.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The development comes a little over a month after Notepad++&nbsp;<a href=\"https:\/\/thehackernews.com\/2025\/12\/threatsday-bulletin-spyware-alerts.html#update-closes-hijack-flaw\" rel=\"noreferrer noopener\" target=\"_blank\">released<\/a>&nbsp;version 8.8.9 to address an issue that resulted in traffic from WinGUp, the Notepad++ updater, being &#8220;occasionally&#8221; redirected to malicious domains, resulting in the download of poisoned executables.<\/p>\n\n\n<a class=\"wp-block-read-more\" href=\"https:\/\/familiebuckens.nl\/index.php\/2026\/02\/02\/notepad-official-update-mechanism-hijacked-to-deliver-malware-to-select-users\/\" target=\"_self\"><a href=\"https:\/\/thehackernews.com\/2026\/02\/notepad-official-update-mechanism.html\">Notepad++ Official Update Mechanism Hijacked to Deliver Malware to Select Users<\/a><span class=\"screen-reader-text\">: Notepad++ Official Update Mechanism Hijacked to Deliver Malware to Select Users<\/span><\/a>","protected":false},"excerpt":{"rendered":"<p>The maintainer of Notepad++ has revealed that state-sponsored attackers hijacked the utility&#8217;s update mechanism to redirect update traffic to malicious servers instead. &#8220;The attack involved [an] infrastructure-level compromise that allowed malicious actors to intercept and redirect update traffic destined for notepad-plus-plus.org,&#8221; developer Don Ho&nbsp;said. &#8220;The compromise occurred at the hosting&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[12],"tags":[72,13],"class_list":["post-895","post","type-post","status-publish","format-standard","hentry","category-supply-chain-attack","tag-72","tag-china"],"_links":{"self":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/895","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/comments?post=895"}],"version-history":[{"count":1,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/895\/revisions"}],"predecessor-version":[{"id":896,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/895\/revisions\/896"}],"wp:attachment":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/media?parent=895"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/categories?post=895"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/tags?post=895"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}