“`html
Notepad++ Supply Chain Attack: Details and Mitigation
In a meaningful security incident spanning much of 2025, Notepad++ users were targeted by a malicious campaign involving the compromise of its update infrastructure.While the situation is now under control, with mitigation efforts completed by December 2025, the attack highlights the growing risk of supply chain vulnerabilities in software distribution. This article details the incident, the investigation, the remediation steps taken, and what users should know to stay protected.
timeline of the Attack
The attack began in June 2025, with malicious actors gaining access to the shared hosting infrastructure of notepad-plus-plus.org. This allowed them to intercept and redirect update traffic to servers controlled by the attackers. From June through September 2, 2025, the hosting server itself was compromised. Even after losing direct server access, attackers retained credentials to internal services until December 2, 2025, enabling continued redirection of Notepad++ update traffic.Security experts estimate the core attack subsided
Worth a look