Notepad++ was hijacked by state-sponsored actors, who compromised the hosting server and redirected update traffic to malicious servers, potentially allowing them to exploit vulnerabilities in older versions of the software. The attack is believed to have started in June 2025 and was discovered in December 2025. The Notepad++ website has been migrated to a new hosting provider with stronger security practices, and updates have been made to the software to enhance security. The attackers are suspected to be a Chinese state-sponsored group, targeting specific users, particularly in Asia.