Microsoft Defender for Business: What You Need to Know
- Cyber Security
- M365

Notepad++ is a tool almost every engineer uses, which is exactly why its recent compromise matters. In early February 2026, the Notepad++ maintainer confirmed a targeted supply chain attack that quietly hijacked update traffic for months.
If you manage endpoints, software distribution, or security controls, this is worth your full attention. Not because Notepad++ code was hacked, but because the attack shows how much trust we place in update infrastructure.
If you want a second set of eyes on how third-party software is managed in your environment, this is the sort of scenario we help organisations review. Get in touch to learn more.
This was not a typical malware incident and not a vulnerability in the Notepad++ codebase.
According to updates shared by the Notepad++ maintainer and independent research by Rapid7 and Kaspersky, the attack unfolded like this:
The compromise window is estimated to span June 2025 through early December 2025, with some disagreement between investigators on the exact end date. The maintainer estimates full attacker access was definitively terminated on 2 December 2025.
Importantly, there is no evidence the Notepad++ source code, repositories, or signing keys were breached. This was a hosting and update delivery problem, not a development one.
Official disclosure: https://notepad-plus-plus.org/news/hijacked-incident-info-update/
Here’s how the events unfolded.
This detail matters. It shows how credential hygiene and internal service access can extend the blast radius of a breach well beyond the initial intrusion.
This incident is a textbook supply chain compromise, but with a few twists.
Attackers did not blanket-infect users. Instead, they:
This dramatically reduced detection and noise.
Analysis from Rapid7 and Kaspersky identified a backdoor dubbed Chrysalis, delivered via tampered update installers.
Key technical details:
Chrysalis capabilities included:
Rapid7 analysis: https://thehackernews.com/2026/02/notepad-hosting-breach-attributed-to.html
With medium confidence, researchers attributed the activity to Lotus Blossom, a China-linked threat actor (also known as Billbug, Lotus Panda, Spring Dragon, Thrip, Raspberry Typhoon or Bronze Elgin).
Targets included:
This was espionage-driven, not mass malware distribution.
There are three reasons this incident stands out.
Notepad++ is ubiquitous. It runs on privileged workstations, servers, and jump boxes. That makes it an attractive pivot point.
Many environments implicitly trust software updaters. If the updater runs, it is assumed safe. This attack broke that assumption without touching the codebase.
The low infection volume meant traditional detection tools had little to correlate. No widespread outbreaks. No obvious indicators.
For IT teams, this reinforces an uncomfortable truth. If a legitimate update channel is compromised, traditional controls struggle unless additional verification exists.
To their credit, the Notepad++ maintainer moved quickly once the scope was understood.
Key changes include:
Users are strongly advised to manually install v8.9.1 or later.
Official update notes: https://notepad-plus-plus.org/news/v889-released/
One important limitation remains. There are no published Indicators of Compromise (IoCs) from the Notepad++ team due to the lack of concrete artefacts in hosting logs. Kaspersky and Rapid7 have since published their own findings with more technical detail.
If Notepad++ exists anywhere in your environment, take this seriously but stay calm.
This is not about banning useful tools. It is about controlling how they enter and update within your environment.
This incident lands close to home. Australian organisations were among those targeted.
Key takeaways:
For councils, schools, MSPs, and mid-sized enterprises, this reinforces the need for basic discipline. Asset visibility, update control, and endpoint monitoring still matter more than shiny tools.
The Notepad++ compromise was not loud, fast, or widespread. That is what makes it dangerous.
A trusted tool, a trusted update channel, and a long dwell time. No zero-day. No user clicking dodgy links. Just infrastructure trust quietly abused.
If you have not reviewed how third-party tools are deployed and updated across your environment, this is your nudge to do it properly.
If you want help pressure-testing your software supply chain controls, you can get in touch with us here.

Got questions, ideas, or just want to chat? We'd love to hear from you! Reach out to us anytime, and we'll get back to you with all the help and information you need.