{"id":220454,"date":"2026-02-02T18:09:34","date_gmt":"2026-02-02T18:09:34","guid":{"rendered":"https:\/\/entertainment.runfyers.com\/index.php\/2026\/02\/02\/notepad-says-chinese-government-hackers-hijacked-its-software-updates-for-months-techcrunch\/"},"modified":"2026-02-02T18:09:34","modified_gmt":"2026-02-02T18:09:34","slug":"notepad-says-chinese-government-hackers-hijacked-its-software-updates-for-months-techcrunch","status":"publish","type":"post","link":"https:\/\/entertainment.runfyers.com\/index.php\/2026\/02\/02\/notepad-says-chinese-government-hackers-hijacked-its-software-updates-for-months-techcrunch\/","title":{"rendered":"Notepad++ says Chinese government hackers hijacked its software updates for months | TechCrunch"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\">The developer of the popular open source text editor Notepad++ has confirmed that hackers hijacked the software to deliver malicious updates to users over the course of several months in 2025.<\/p>\n<p class=\"wp-block-paragraph\">In a <a href=\"https:\/\/notepad-plus-plus.org\/news\/hijacked-incident-info-update\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">blog post<\/a> published Monday, Notepad++ developer Don Ho said that the cyberattack was likely carried out by hackers associated with the Chinese government between June and December 2025, citing multiple analyses by security experts who examined the malware payloads and attack patterns. Ho said this \u201cwould explain the highly selective targeting\u201d seen during the campaign.<\/p>\n<p class=\"wp-block-paragraph\">Rapid7, which <a rel=\"nofollow noopener\" href=\"https:\/\/www.rapid7.com\/blog\/post\/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit\/\" target=\"_blank\">investigated the incident<\/a>, attributed the hacking to Lotus Blossom, a long-running espionage group known to work for China, and said the hacks targeted government, telecom, aviation, critical infrastructure, and media sectors.<\/p>\n<p class=\"wp-block-paragraph\">Notepad++ is one of the longest-running open source projects, spanning more than two decades, and it counts at least tens of millions of downloads to date, including by employees at organizations around the world.\u00a0\u00a0<\/p>\n<p class=\"wp-block-paragraph\">According to Kevin Beaumont, a security researcher who <a href=\"https:\/\/doublepulsar.com\/small-numbers-of-notepad-users-reporting-security-woes-371d7a3fd2d9\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">first discovered the cyberattack and wrote up his findings<\/a> in December, the hackers compromised a small number of organizations \u201cwith interests in East Asia\u201d after someone unwittingly used a tainted version of the popular software. Beaumont said that the hackers were able to gain \u201chands-on\u201d access to the computers of victims who were running hijacked versions of Notepad++.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Ho said that the \u201cexact technical mechanism\u201d of how the hackers broke into his servers remains under investigation, but provided some details as to how the attack went down.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">In the blog, Ho said that Notepad++\u2019s website was hosted on a shared hosting server. The attackers \u201cspecifically targeted\u201d Notepad++\u2019s web domain with the goal of exploiting a bug in the software to redirect some users to a malicious server run by the hackers. This allowed the hackers to deliver malicious updates to certain users who had requested a software update, until the <a href=\"https:\/\/notepad-plus-plus.org\/news\/v889-released\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">bug was fixed in November<\/a> and the hackers\u2019 access was terminated in early December.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWe do have logs indicating that the bad actor tried to re-exploit one of the fixed vulnerabilities; however, the attempt did not succeed after the fix was implemented,\u201d wrote Ho.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">In an email, Ho told TechCrunch that his hosting provider confirmed his shared server was compromised but that the provider did not say how the hackers initially broke in.<\/p>\n<p class=\"wp-block-paragraph\">Ho apologized for the incident, and urged users to download the <a href=\"https:\/\/notepad-plus-plus.org\/downloads\/v8.9.1\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">most recent version<\/a> of his software, which contains a fix for the bug.<\/p>\n<p class=\"wp-block-paragraph\">The cyberattack targeting Notepad++ users is somewhat reminiscent of the 2019-2020 cyberattack affecting customers of SolarWinds, a software company that makes IT and network management tools for large Fortune 500 organizations, including government departments. Russian government spies <a href=\"https:\/\/techcrunch.com\/2021\/02\/23\/solarwinds-hackers-targeted-nasa-federal-aviation-administration-networks\/\" target=\"_blank\" rel=\"noopener\">hacked into the company\u2019s servers<\/a> and secretly planted a backdoor in its software, allowing the Russian spies to access data on those customers\u2019 networks once the update had rolled out.<\/p>\n<p class=\"wp-block-paragraph\">The SolarWinds breach affected several government agencies, including Homeland Security and the Departments of Commerce, Energy, Justice, and State.<\/p>\n<p class=\"wp-block-paragraph\"><em>Updated with a response from Ho and with additional details from Rapid7.<\/em><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2026\/02\/02\/notepad-says-chinese-government-hackers-hijacked-its-software-updates-for-months\/\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The developer of the popular open source text editor Notepad++ has confirmed that hackers hijacked the software to deliver malicious updates to users over the course of several months in 2025. In a blog post published Monday, Notepad++ developer Don Ho said that the cyberattack was likely carried out by hackers associated with the Chinese [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":220455,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"class_list":{"0":"post-220454","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tech"},"_links":{"self":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/220454","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=220454"}],"version-history":[{"count":0,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/220454\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/220455"}],"wp:attachment":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=220454"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=220454"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=220454"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}