Can Notepad++ Be Hacked? How MSPs Identify Real vs Fake Threats
Notepad++ update traffic was hacked starting in June 2025. The hack remained undisclosed until the Notepad++ hosting developer issued a…
Can Notepad++ Be Hacked? How MSPs Identify Real vs Fake Threats

Notepad++ update traffic was hacked starting in June 2025. The hack remained undisclosed until the Notepad++ hosting developer issued a statement on February 2, 2026.
According to The Hacker News, a Chinese state-sponsored actor known as Lotus Blossom was responsible for the Notepad++ hack. Rapid7 reported that the attack enabled the delivery of a previously undocumented backdoor to users of the open-source editor. The backdoor was codenamed Chrysalis.
Notepad++ maintainer Don Ho provided additional details on the incident. He said, “A compromise at the hosting provider level allowed threat actors to hijack update traffic starting in June 2025. The attackers selectively redirected requests from specific users to malicious servers. This allowed them to serve a tampered update by exploiting gaps in the update verification controls.
The weakness was fixed with Notepad++ version 8.8.9, released in December 2025. The hosting provider was compromised between June 2025 and December 2, 2025. During this period, attackers performed targeted traffic redirection. Access was terminated in December. After that, Notepad++ migrated to a new hosting provider with stronger security and rotated all credentials.
Rapid7 reported no evidence that the official plugin system or updater mechanism was directly used to distribute malware.
After the investigation, the hosting provider rotated all secrets and issued recommended actions to be performed by the Notepad++ developer:
-
Change credentials for FTP/SFTP, MySQL, and SSH.
-
Review WordPress admin accounts, remove unnecessary users, and reset all the passwords.
-
Update WordPress core, themes, and plugins, and turn on automatic updates if applicable.
As a safety measure, WinGup now verifies installer certificates and signatures for Notepad++ version 8.8.9. The update XML is now cryptographically signed.
The developer also outlined plans to enforce mandatory certificate signature verification in version 8.9.2. The release is expected within approximately one month.
For MSPs managing multiple environments, visibility into endpoint behavior and update activity is critical. SafeAeon provides managed detection and response to help teams track and respond to this kind of risk.
메타데이터
- post_id
- c7ddccc474a4
- slug
- can-notepad-be-hacked-how-msps-identify-real-vs-fake-threats-c7ddccc474a4
- url
- https://medium.com/@safeaeon-inc/can-notepad-be-hacked-how-msps-identify-real-vs-fake-threats-c7ddccc474a4
- canonical_url
- https://medium.com/@safeaeon-inc/can-notepad-be-hacked-how-msps-identify-real-vs-fake-threats-c7ddccc474a4
- author_url
- https://medium.com/@safeaeon-inc
- status
- ok
- fetched_at
- 2026-07-16 19:47:57