Iran Memorial

Notepad++ updates got hijacked for months and could have spied for China

The Verge2/2/2026 – 2/3/2026

Summary

Users of the text and code editor Notepad++ may have unknowingly downloaded a malicious update due to a security breach that occurred from June 2025 until December 2, 2025. The developer of Notepad++, Don Ho, reported that hackers, likely associated with the Chinese government, hijacked the software's update mechanism. This incident allowed the attackers to deliver backdoored versions of the popular free source code editor and note-taking app for Windows, potentially compromising users' devices. The breach involved the app's former hosting provider, where traffic from certain targeted users was selectively redirected to servers controlled by the attackers. Investigations by multiple security experts confirmed that the attacks were strategically aimed at specific individuals or organizations, although the exact demographics of the targeted users and the nature of the malicious files remain unclear. This selective targeting reflects a common tactic in state-sponsored cyber operations, where specific goals are pursued through the exploitation of widely used software. The incident underscores the ongoing threat posed by state-sponsored cyberattacks, particularly as they increasingly exploit vulnerabilities in widely used software. The implications of such breaches extend beyond immediate security concerns, highlighting the need for robust cybersecurity measures. As digital tools become integral to daily operations, the vulnerabilities inherent in software ecosystems become more pronounced, emphasizing the importance of vigilance against sophisticated cyber threats.

Share:XRedditLinkedIn

Advertisement

Cluster Activity

2
1
1
2026-02-022026-02-04

Lindy Score Breakdown (V4.2)

15d
Age
4
Sources
from cluster
338
Hours Since Seen
Final Score0/100
CategoryAntiLindy
StatusArchived
Recency Multiplier1% (0.5^338/48)
Hero EligibleNo
Score is 0 because recency decay (0.5^338/48 = 0.007590) reduced it below 0.5

Story Timeline

  1. 2026-02-02
    Notepad++ updates got hijacked for months and could have spied for China (current)
  2. 2026-02-03
  3. 2026-02-04

Score BreakdownRisk 25

Source Reputation: Low-trust source (6/20 pts)
Consensus: Strong consensus: 4 independent sources
Age: 14 days - proven survivor

Stories gain Lindy status through source reputation, network consensus, and time survival.

Same Story from 4 sources

Breaking Similar stories

Anti-Lindy Similar stories