news.volyx.in

Notepad++ hijacked by state-sponsored actors (notepad-plus-plus.org)

917 points by mysterydip · 170 days ago · 519 comments on HN

Article summary

Notepad++ was hijacked by state-sponsored actors, who compromised the hosting server and redirected update traffic to malicious servers, potentially allowing them to exploit vulnerabilities in older versions of the software. The attack is believed to have started in June 2025 and was discovered in December 2025. The Notepad++ website has been migrated to a new hosting provider with stronger security practices, and updates have been made to the software to enhance security. The attackers are suspected to be a Chinese state-sponsored group, targeting specific users, particularly in Asia.

Main themes

  • State-sponsored hacking
  • Software security
  • Supply chain attacks
  • Notepad++ compromise
  • Chinese state-sponsored group
  • Targeted attacks

What commenters say

  • The use of a self-signed certificate in Notepad++ made it vulnerable to manipulation by attackers, allowing them to create and push malicious updates to users.
  • The attack was likely carried out by a Chinese state-sponsored group, targeting specific users, particularly in Asia, in order to exploit vulnerabilities in older versions of the software.
  • Some users feel that the Notepad++ developer should take responsibility for the security breach, rather than blaming the hosting company, as the use of a self-signed certificate was a known vulnerability.
  • The inclusion of political messaging in software updates can be seen as a form of activism, but some users feel that it is inappropriate and frustrating, and that there are better venues for such messaging.
  • Others argue that the messaging is necessary to raise awareness about important issues, and that it can be an effective way to reach a large audience.
  • Some users are concerned that the attack may have compromised their personal data, and that the breach may have been more widespread than initially thought.
  • The incident highlights the importance of robust security practices, including the use of secure certificates and regular updates, to prevent similar attacks in the future.