Chipp.in Tech News and Reviews

Windows, Security & Privacy, Open Source and more

Menu
  • Home
  • Windows
  • Security & Privacy
  • Gaming
  • Guides
  • Windows 11 Book
  • Contact
  • RSS Feed
Menu

Why You Need to Update Notepad++ Immediately

Posted on February 2, 2026February 2, 2026 by Martin Brinkmann

The popular open source plain text editor has become the target of state-sponsored hackers, according to a blog post. The Notepad++ developer released a detailed post-mortem on a severe supply chain attack that occurred between June and December 2025.

By compromising the application’s hosting provider, state-sponsored hackers were able to redirect update traffic to serve malicious files to users of the text editor.

It all started in 2025

When the developer of Notepad++ put out a security warning in December 2025, it was immediately clear that something critical happened. The blog post confirmed that a vulnerability of the updating process had been exploited for some time. Traffic “was occasionally redirected to malicious servers”, which resulted “in the download of compromised executables” according to the message.

The developer released Notepad++ 8.8.9 to address the issue. That version had been hardened according to the report by adding verification steps to the update process. In other words, Notepad++ checks whether the signature and the certificate of the downloaded installer (the new version) check out. If they do not, updating is aborted.

New information comes to light

The latest version of Notepad++ is 8.9.1 at the time of writing.

Today, a new blog post was published that provides detailed information on the incident. Here are the details:

  • The Breach Method: The attack was not a vulnerability in the Notepad++ code itself, but a compromise of its hosting provider’s infrastructure.
  • The Timeline: The hijacking occurred over a six-month period, starting in June 2025 and lasting until it was discovered and shut down on December 2, 2025.
  • State-Sponsored Attribution: Security researchers (including those from HarfangLab and ESET) linked the activity to “Taidoor,” a malware strain associated with Chinese state-sponsored threat actors.
  • Targeted Delivery: The attackers used a “Man-in-the-Middle” tactic via the WinGUp updater; however, they did not target every user, instead selectively delivering malicious updates to specific IP addresses or regions.
  • Infrastructure Migration: In response, Notepad++ has completely abandoned its previous hosting provider and migrated all binaries and update manifests to a new, more secure infrastructure.
  • Enhanced Security Measures: To prevent future incidents, new versions include mandatory signature verification and certificate pinning for all automated updates.
  • User Action Required: Users are urged to ensure they are running the latest version of Notepad++ and to be wary of any version installed or updated between the June and December window.

The latest version is Notepad 8.9.1. You can download it from the official website to make sure that a potentially compromised version is replaced.

You can check the installed version by opening Notepad++ and selecting ? > About Notepad++, or by pressing F1.

Tags:
Category: Security & Privacy

Post navigation

← It’s Change Your Password Day (again): Here is Why You Should Probably Do Nothing

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Support This Site

If you like what I do please support me!

Any tip is appreciated. Thanks!
  • February 2, 2026 by Martin Brinkmann Why You Need to Update Notepad++ Immediately
  • February 1, 2026 by Martin Brinkmann It’s Change Your Password Day (again): Here is Why You Should Probably Do Nothing
  • January 31, 2026 by Martin Brinkmann Total Opt-Out: How to Use Firefox 148’s New Master Switch to Block All AI Features
  • January 30, 2026 by Martin Brinkmann The Road to Recovery: How Microsoft Plans to Make You Love Windows Again
  • January 30, 2026 by Martin Brinkmann Google Chrome Gets a Major Upgrade with Gemini 3 and Auto-Browse

About

We talk, write and dream about Technology 24/7 here at Chipp.in. The site, created by Martin Brinkmann in 2023, focuses on well-researched tech news, reviews, guides, help and more.

Legal Notice

Our commitment

Many websites write about tech, but chipp.in is special in several ways. All of our guides are unique, and we will never just rehash news that you find elsewhere.

Read the About page for additional information on the site and its founder and author.

Support Us

We don't run advertisement on this site that tracks users. If you see ads, they are static links. Ads, including affiliate links, never affect our writing on this site.

Here is a link to our privacy policy

©2026 Chipp.in Tech News and Reviews