Skip to main content
See every side of every news story
Published loading...Updated

Notepad++ users take note: It's time to check if you're hacked

  • On Monday, Notepad++ maintainer Don Ho said suspected Chinese state-sponsored attackers hijacked the update mechanism by redirecting some users to malicious update servers.
  • Investigators reported the intrusion started in June 2025, and attackers retained internal credentials until December 2, despite a temporary loss in early September.
  • Security researcher Kevin Beaumont said at least three organizations with East Asia interests faced targeted Notepad++ update hijacks, leading to hands-on keyboard intrusions.
  • Notepad++ migrated hosting, rotated credentials, patched vulnerabilities, and confirmed malicious activity stopped; version 8.8.9 added signature verification and version 8.9 removed the self-signed root certificate, which users were urged to remove.
  • With broad attention, researchers and reporters continue to investigate Notepad++, which has tens of millions of users, drawing scrutiny from CISA and media like The Register; Kevin Beaumont praised the developer.
Insights by Ground AI
Podcasts & Opinions

30 Articles

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 75% of the sources are Center
75% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

IT Security News - cybersecurity, infosecurity news broke the news in on Monday, February 2, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal