Popular open-source coding application targeted in Chinese-linked supply-chain attack

A Chinese-linked cyberespionage group with a long history hijacked ⁠the update process for the popular code editing platform Notepad++ to deliver a custom backdoor and other malware to targeted users, the program’s developer and cybersecurity researchers said on Monday.

Don Ho, the French-based developer of Notepad++, said in a blog posted to the project’s website on ‌Monday that malicious actors had ‌targeted the update process for certain targeted users beginning in June 2025. The hackers had access to the hosting server used for Notepad++ updates until September ‌2, 2025, but maintained credentials to some hosting services until December 2, 2025, according to Ho.

Read more

You may also like

Comments are closed.

More in IT