Notepad++ disclosed a supply chain attack from June to December 2025 where state-sponsored threat actors linked to China compromised a third-party hosting provider to selectively redirect update requests from high-value targets to malicious servers. The attackers exploited insufficient verification controls in the WinGUp
•2m read time• From arcticwolf.com
Table of contents
Manually Update to a Safe Notepad++ VersionSort: