Quick Summary
The Securityish Brief
Notepad++, a widely used text and source code editor for Windows, faced a supply chain attack in June 2025 when its shared hosting server was compromised. Attackers exploited weaknesses in the update mechanism, delivering malicious updates to users. This incident was confirmed by Notepad++ maintainer Don Ho earlier this month, highlighting the risks associated with unverified software updates.
The vulnerabilities included an unsigned XML file that allowed the auto-updater, WinGUp, to download updates from unauthorized domains. Additionally, prior to the release of Notepad++ v8.8.9 on December 9, 2025, WinGUp did not verify the code signing certificate of the downloaded installer. These oversights enabled attackers to execute malicious payloads, including Cobalt Strike Beacon and the Chrysalis backdoor, impacting organizations across Southeast Asia, South America, the US, and Europe.
In response to this breach, Notepad++ has implemented critical security measures in its latest version, v8.9.2, released on February 18, 2026. The update process now verifies the signed XML file and the installer signature, effectively closing the vulnerabilities that were previously exploited. Ho stated that these enhancements have made the update process “effectively unexploitable.”
Additional security improvements include the removal of the libcurl.dll dependency to mitigate DLL side-loading risks, disabling insecure cURL SSL options, and restricting plugin management execution to programs signed with the same certificate as WinGUp. These changes are vital for protecting users from future attacks.
Users are strongly encouraged to upgrade to the latest version and to download Notepad++ only from its official GitHub repository or website to avoid counterfeit downloads that may distribute malware.
Understanding the Risks
The Notepad++ incident underscores the significant risks associated with supply chain attacks, where vulnerabilities in software distribution channels can lead to widespread malware infections. Organizations and users must remain vigilant about the sources of their software updates and ensure that they are using verified and trusted channels.
As cybercriminals increasingly target software supply chains, it is crucial for users to adopt best practices for software security. This includes regularly updating software, verifying digital signatures, and being cautious about downloading applications from unofficial sources.
Key Takeaways
- Upgrade to Notepad++ v8.9.2 to benefit from enhanced security features.
- Download Notepad++ only from the official GitHub repository or website to avoid malware.
- Verify digital signatures of software updates to ensure authenticity.
- Be cautious of downloading software from unofficial or spoofed websites.
- Regularly check for updates and apply them promptly to maintain security.
Key Terms & Concepts
- Supply Chain Attack: In this article, a supply chain attack refers to a breach where attackers compromise the software distribution process to deliver malicious updates.
- Cobalt Strike Beacon: Cobalt Strike Beacon is a type of malware used for establishing command and control communication during cyber attacks.
- Chrysalis Backdoor: Chrysalis Backdoor is a malicious tool that allows attackers to gain unauthorized access to systems.
- Code Signing Certificate: A code signing certificate is a digital certificate that verifies the authenticity and integrity of software updates.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.