Notepad++ Official Update Mechanism Hijacked to Deliver Malware to Select Users
The maintainer of Notepad++ has reported that state-sponsored attackers hijacked the utility's update mechanism to divert update traffic to malicious servers instead.
The attack involves [an] infrastructure-level compromise that allowed malicious actors to intercept and divert update traffic destined for notepad-plus-plus.org, developer Don Ho stated. The compromise occurred at the hosting provider level rather than through weaknesses in Notepad++ code itself.
Ho continued, "The precise mechanism through which this was realized is currently being investigated."
The development comes a little over a month after Notepad++ released version 8.8.9 to solve an issue that resulted in traffic from WinGUp, the Notepad++ updater, being "occasionally" routed to malicious domains, resulting ...

