Chipp.in Tech News and Reviews

Windows, Security & Privacy, Open Source and more

Menu
  • Home
  • Windows
  • Security & Privacy
  • Gaming
  • Guides
  • Windows 11 Book
  • Contact
  • RSS Feed
Menu

Why You Need to Update Notepad++ Immediately

Posted on February 2, 2026February 2, 2026 by Martin Brinkmann

The popular open source plain text editor has become the target of state-sponsored hackers, according to a blog post. The Notepad++ developer released a detailed post-mortem on a severe supply chain attack that occurred between June and December 2025.

By compromising the application’s hosting provider, state-sponsored hackers were able to redirect update traffic to serve malicious files to users of the text editor.

It all started in 2025

When the developer of Notepad++ put out a security warning in December 2025, it was immediately clear that something critical happened. The blog post confirmed that a vulnerability of the updating process had been exploited for some time. Traffic “was occasionally redirected to malicious servers”, which resulted “in the download of compromised executables” according to the message.

The developer released Notepad++ 8.8.9 to address the issue. That version had been hardened according to the report by adding verification steps to the update process. In other words, Notepad++ checks whether the signature and the certificate of the downloaded installer (the new version) check out. If they do not, updating is aborted.

New information comes to light

The latest version of Notepad++ is 8.9.1 at the time of writing.

Today, a new blog post was published that provides detailed information on the incident. Here are the details:

  • The Breach Method: The attack was not a vulnerability in the Notepad++ code itself, but a compromise of its hosting provider’s infrastructure.
  • The Timeline: The hijacking occurred over a six-month period, starting in June 2025 and lasting until it was discovered and shut down on December 2, 2025.
  • State-Sponsored Attribution: Security researchers (including those from HarfangLab and ESET) linked the activity to “Taidoor,” a malware strain associated with Chinese state-sponsored threat actors.
  • Targeted Delivery: The attackers used a “Man-in-the-Middle” tactic via the WinGUp updater; however, they did not target every user, instead selectively delivering malicious updates to specific IP addresses or regions.
  • Infrastructure Migration: In response, Notepad++ has completely abandoned its previous hosting provider and migrated all binaries and update manifests to a new, more secure infrastructure.
  • Enhanced Security Measures: To prevent future incidents, new versions include mandatory signature verification and certificate pinning for all automated updates.
  • User Action Required: Users are urged to ensure they are running the latest version of Notepad++ and to be wary of any version installed or updated between the June and December window.

The latest version is Notepad 8.9.1. You can download it from the official website to make sure that a potentially compromised version is replaced.

You can check the installed version by opening Notepad++ and selecting ? > About Notepad++, or by pressing F1.

Tags:
Category: Security & Privacy

Post navigation

← It’s Change Your Password Day (again): Here is Why You Should Probably Do Nothing
No More Free Background Play: Google Patches one of YouTube’s Biggest Mobile Loophole →

15 thoughts on “Why You Need to Update Notepad++ Immediately”

  1. VioletMoon says:
    February 2, 2026 at 4:00 pm

    “The latest version is Notepad 8.9.1.” Already there–just checked. I don’t think it updated on its own. Hmmm . . . maybe one of the programs I use updated it. Either way, thanks.

    PatchPC; WAU; UniGet.

    Click on the ? mark; I guess that equals Help. Then, one can manually update or check version in About.

    Reply
  2. KM says:
    February 2, 2026 at 4:41 pm

    Wow that is crazy, so I wonder if this is one of those situations where they poisoned the supply chain and then targeted specific targets within that.

    Reply
  3. Dave says:
    February 2, 2026 at 11:44 pm

    Just a question, Wouldnt running Notepad++ to see what version you have also execute the malicious payload if Notepad++ has already been compromised ?

    BTW: A long standing Ghacks visitor who now visits ChippIn instead 🙂

    Reply
    1. Mystique says:
      February 5, 2026 at 3:47 am

      No official comment but I believe that Ghacks is 100% AI written documents now and there are no original staff members writing at the Ghacks site or involved in any capacity there as of 2026.

      Reply
  4. Tachy says:
    February 3, 2026 at 5:14 am

    My version of Notepad++ has a build date in 2023.

    As a habit I disable “check for updates” on most everything and block everything in the firewall. I manually download and install new versions myself whenever possible.

    Notepad++ has no reason to access the internet on my PC.

    Am I paranoid? Perhaps. Did I avoid this issue? Completely 😁

    Reply
    1. Tom Hawack says:
      February 3, 2026 at 2:30 pm

      If you’re paranoid then I am as well. And for software that checks for updates without an option to disable it, I add the update link to my system-wide block-list.

      Reply
  5. Basement Gamer XD says:
    February 3, 2026 at 6:30 am

    OMG!!

    I mean, first Microsoft completely ruins the simple, no frills notepad. You remove that and install Notepad++ just to get some sense of normalcy and restore notepad to basic functionality again and then this happens! World? What the heck? How many people, prior to Microsoft making notepad a little “recall” pad and something to drop AI into, use it for more than just jotting down well, a few notes?

    I have only ever used it to copy/paste a line of code, a confirmation number, an email address or maybe just a temporary password. Notepad imho is not supposed to be a place you’d store document style information or long lost secrets. Why so much interest?

    Anyway, I use classic notepad and have done so for a long time. It truly restores the Windows XP/7 vibe and simple functionality with no fuss. I did find Notepad++ to be more than I wanted and Classic Notepad works just fine.

    https://win7games.com/#notepad

    Remove that ridiculous, AI infested, Win11 notepad first, then install this. It will want you to manually confirm that it (classic notepad), is going to be set for default but since you removed it prior to install, you won’t see the win11 version listed. Ignore and move on.

    Thats it! Notepad like your Grandad used to use! LOL

    Oh, Windows 11 does pop up now and then, informing you that there is an “upgrade” to your version of notepad. Thanks Microsoft! I decline your fine offer :/

    Reply
  6. Tachy says:
    February 3, 2026 at 3:03 pm

    @Martin

    Windows Defender just flagged WinAeroTweaker Version 1.64.1 as a trojan after this mornings manual definition update.

    I rolled it back to Version 1.62 and WinDef ignores it again.

    Reply
  7. VioletMoon says:
    February 3, 2026 at 4:49 pm

    Martin-this has nothing to do with Notepad++. I went to gHacks and wanted to search the archives, but the “search” function is disabled. That means all of your old tutorials, many of which are still relevant, are inaccessible. Was this planned? Part of the agreement with the transfer of ownership? Is there a way to restore search function?

    Thanks!

    Reply
    1. Martin Brinkmann says:
      February 3, 2026 at 5:58 pm

      That is unfortunate. I was not involved in the sale, had no say, was not asked. You could try the site: command in search engines to maybe find tutorials.

      Reply
      1. VioletMoon says:
        February 3, 2026 at 11:04 pm

        Oh! Thankful–site:ghacks.net and then insert term like

        site:ghacks.net firefox profiles

        site:ghacks.net best compression software

        Never used the command; never knew about it.

        Here’s Martin still teaching–!

        Reply
    2. Tom Hawack says:
      February 3, 2026 at 7:04 pm

      Indeed, “Search” has disappeared on gHacks.
      Remains what we all know, i.e. with noai.DuckDuckGo:
      [https://noai.duckduckgo.com/?q=Notepad++ +site:ghacks.net]

      Ghacks has but the name of what it was when managed by Martin, but fortunately his articles are accessible; and accessed as far as I and many others are concerned.

      Reply
    3. Basement Gamer XD says:
      February 3, 2026 at 9:29 pm

      Martin:

      Do you have backup copies of the work of you’ve done over the years? Maybe an SQL or other type of database? Backups in a different format?

      If so, perhaps an archive page here for links to past articles. Happy to help out with database reconstruction, Standard SQL, php/MySql or whatever it was stored in.

      Reply
      1. Martin Brinkmann says:
        February 4, 2026 at 7:39 am

        I do not. Part of the deal. It is their property now, can do whatever they want with it. Thanks for the offer though. I plan to write a few tutorials that are still valid, some needed updating anyway.

        Reply
  8. Juan M says:
    February 3, 2026 at 8:32 pm

    I use the portable version of Notepad++, it includes the updater but does not work for updating a portable install. It wants to download the regular installer even in this version so I don’t use it.

    When I want to update, I download the new portable compressed file from the official Notepad++ page.

    Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Support This Site

If you like what I do please support me!

Any tip is appreciated. Thanks!
  • February 18, 2026 by Martin Brinkmann Mozilla ends support for Firefox on Windows 7 and 8/8.1
  • February 17, 2026 by Martin Brinkmann Chrome Stable Channel Update: Emergency Fix for Active CSS Exploit
  • February 16, 2026 by Martin Brinkmann YouTube is reportedly hiding video descriptions and comments for some adblock users
  • February 15, 2026 by Martin Brinkmann Trading In Your Android? Here Are the Mandatory Steps to Follow
  • February 14, 2026 by Martin Brinkmann Rent, Pay, Return: The OMEN Laptop Subscription Math That HP Hopes You Won't Do

About

We talk, write and dream about Technology 24/7 here at Chipp.in. The site, created by Martin Brinkmann in 2023, focuses on well-researched tech news, reviews, guides, help and more.

Legal Notice

Our commitment

Many websites write about tech, but chipp.in is special in several ways. All of our guides are unique, and we will never just rehash news that you find elsewhere.

Read the About page for additional information on the site and its founder and author.

Support Us

We don't run advertisement on this site that tracks users. If you see ads, they are static links. Ads, including affiliate links, never affect our writing on this site.

Here is a link to our privacy policy

©2026 Chipp.in Tech News and Reviews