Chinese hacker attack on Notepad++: update mechanism compromised for months

A serious cybersecurity incident has hit Notepad++, the popular open-source text editor used by millions of users worldwide. Between June and December 2025, hackers sponsored by the Chinese government managed to compromise the software’s update system, installing malware on computers of selected organizations.

The attack was particularly sophisticated: hackers breached Notepad++’s hosting provider server and modified the automatic update mechanism. When specific users requested updates, they were secretly redirected to malicious servers that distributed tampered versions of the software. These versions contained a backdoor called “Chrysalis,” which allowed attackers to access compromised systems and conduct reconnaissance operations.

What makes this attack particularly concerning is its targeted nature. The hackers did not target all Notepad++ users but focused on specific organizations, mainly in the telecommunications, financial, and government sectors, with particular attention to those with interests in East Asia. This selective approach made the attack more difficult to detect. The responsible group, known as Lotus Blossom (also called Violet Typhoon, APT31, Raspberry Typhoon, Bilbug, or Spring Dragon), is a Chinese state-sponsored threat actor, known for cyber espionage operations.

To protect their systems from similar attacks, companies should implement more rigorous update verification systems, carefully monitor network connections during software updates, and use security solutions that can detect anomalous behaviors. Individual users should ensure they download software only from official sources and keep their security systems updated.

  • Key points to remember:
  • Software supply chain attacks, like the one on Notepad++, are becoming increasingly common and sophisticated
  • Organizations must pay special attention to the security of automatic software update mechanisms
  • Collaboration between software developers, security experts, and end users is essential to prevent and mitigate these types of attacks

Sources:
Bleeping Computer, TechCrunch, The Hacker News, SecurityWeek, Official Notepad++ Statement

Source: BleepingComputer