Malware & Threats

Notepad++ Patches Updater Flaw After Reports of Traffic Hijacking

Notepad++ found a vulnerability in the way the software updater authenticates update files. 

Notepad++ hijack

Recent Notepad++ releases address a vulnerability that has allowed threat actors to hijack the free source code editor’s updater. 

Security researcher Kevin Beaumont reported in early December that a handful of organizations using Notepad++ had reported experiencing security incidents involving the code editor.

Beaumont said in an update this week that the attacks appeared to have been carried out by threat actors in China, with the attackers leveraging a Notepad++ vulnerability for initial access to the systems of telecoms and financial services firms in East Asia.

Notepad++ developers seem to have known about issues with the updater since at least mid-November, when version 8.8.8 release notes mentioned a security enhancement designed to prevent the application’s updater from being hijacked.

In a post published this week to announce the release of version 8.8.9, Notepad++ confirmed that traffic from the updater (WinGUp) was in some cases redirected to malicious servers, which resulted in compromised executable files being downloaded to the victim’s system.

Notepad++ developers’ investigation led to the discovery of a flaw in the way the updater validates the authenticity and integrity of update files.

Advertisement. Scroll to continue reading.

“In case an attacker is able to intercept the network traffic between the updater client and the Notepad++ update infrastructure, this weakness can be leveraged by an attacker to prompt the updater to download and executed an unwanted binary (instead of the legitimate Notepad++ update binary).”

In the latest version, Notepad++ and the WinGUp component verify the signature of downloaded installers during the update process, and the update is not performed if the check fails.

However, it has yet to be determined exactly how traffic has been hijacked in the wild.

Beaumont, who described the campaign as a supply chain attack, believes threat actors may be hijacking traffic at the ISP level to push malicious updates, but pointed out that significant resources are required to conduct such an attack.

Related: Google Patches Mysterious Chrome Zero-Day Exploited in the Wild

Related: Wide Range of Malware Delivered in React2Shell Attacks

Related: Unpatched Gogs Zero-Day Exploited for Months

Related Content

Artificial Intelligence

China’s Ministry of Foreign Affairs responded to a question about Amodei’s essay by saying that all parties should work together on AI.

Nation-State

The Chinese-language input method editor for Windows can allow attackers to execute arbitrary code remotely.

Artificial Intelligence

Distillation is an ‘attack’ against an AI model designed to capture outputs, understand reasoning processes, and subsequently train a different model.

Artificial Intelligence

New research shows that country-of-origin labels can obscure an AI model’s upstream dependencies, inherited behaviors and potential security risks.

Nation-State

The operation focused on a group named QTFY, which offers hacking services to the Chinese government and others.

Artificial Intelligence

AI infrastructure, including advanced semiconductors mostly made in Taiwan, has become a key point of competition between the U.S. and China.

Supply Chain Security

Over 95% of the affected companies were exposed before the malicious LiteLLM packages were published.

Application Security

The previous GPG signing subkey was inadvertently added to a GitHub repository and Mozilla decided to revoke it.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version