By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Online Tech Guru
  • News
  • PC/Windows
  • Mobile
  • Apps
  • Gadgets
  • More
    • Gaming
    • Accessories
    • Editor’s Choice
    • Press Release
Reading: Notepad++ updates got hijacked for months and could have spied for China
Best Deal
Font ResizerAa
Online Tech GuruOnline Tech Guru
  • News
  • Mobile
  • PC/Windows
  • Gaming
  • Apps
  • Gadgets
  • Accessories
Search
  • News
  • PC/Windows
  • Mobile
  • Apps
  • Gadgets
  • More
    • Gaming
    • Accessories
    • Editor’s Choice
    • Press Release
UK retailer GAME shutters last remaining standalone stores as it enters administration

UK retailer GAME shutters last remaining standalone stores as it enters administration

News Room News Room 2 February 2026
FacebookLike
InstagramFollow
YoutubeSubscribe
TiktokFollow
  • Subscribe
  • Privacy Policy
  • Contact
  • Terms of Use
© Foxiz News Network. Ruby Design Company. All Rights Reserved.
Online Tech Guru > News > Notepad++ updates got hijacked for months and could have spied for China
News

Notepad++ updates got hijacked for months and could have spied for China

News Room
Last updated: 2 February 2026 21:12
By News Room 3 Min Read
Share
Notepad++ updates got hijacked for months and could have spied for China
SHARE

Users of the text and code editor Notepad++ may have unknowingly downloaded a malicious update for the app after its shared hosting servers were hijacked last year. On Monday, the app’s developer, Don Ho, posted an update on the attack with more details, including that the hackers were “likely a Chinese state-sponsored group” and that the app’s servers were vulnerable for roughly six months from June through December 2nd, 2025.

The post explains that the hijacking occurred on the app’s unnamed, now-former hosting provider’s end, stating that “Traffic from certain targeted users was selectively redirected to attacker-controlled served malicious update manifests.” When victims were redirected, their app update could be replaced with a malicious executable that, according to independent cybersecurity expert Kevin Beaumont, may have given the hackers remote access to a victim’s keyboard.

Don Ho’s post also adds that the attack involved “highly selective targeting” in terms of the victims it redirected away from the legitimate Notepad++ website. Kevin Beaumont noted that the victims he spoke with “are [organizations] with interests in East Asia.” So, while this is a serious security vulnerability, it’s possible that the hackers were busy watching specific people instead of just anyone.

The developer did not specify when they became aware of the attack, but said that “all attacker access was definitively terminated” by December 2nd. The Notepad++ updater has been updated itself with stronger security measures to check for tampering and verify that updates are legitimate.

Notepad++ users should make sure they are on at least version 8.8.9, which addressed the vulnerabilities from the hijacking attack, and they should probably download that version directly from the Notepad++ website. Additionally, Kevin Beaumont suggested users double-check that they’re not using an unofficial version of Notepad++, keep a close eye on activity from “gup.exe,” the app’s updater, and check for a suspicious “update.exe” or “AutoUpdater.exe” file in their TEMP folder.

Notably, Don Ho, the developer of Notepad++, criticized the Chinese government in a 2019 app update. He called that version the “Free Uyghur” edition, and told The Verge at the time that his website had faced DDoS attacks in response.

Share This Article
Facebook Twitter Copy Link
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Elon Musk merges SpaceX with xAI (and X)

Elon Musk merges SpaceX with xAI (and X)

News Room News Room 2 February 2026
FacebookLike
InstagramFollow
YoutubeSubscribe
TiktokFollow

Trending

The Top Picks To Pair With Lorwyn Eclipsed’s Popular Mirrorform Card

The latest Magic: The Gathering set, Lorwyn Eclipsed, is here to kick off the game’s…

2 February 2026

HHS Is Using AI Tools From Palantir to Target ‘DEI’ and ‘Gender Ideology’ in Grants

Since last March, the Department of Health and Human Services has been using AI tools…

2 February 2026

Dyson Deals: WIRED’s Top Pick Pet Vacuum and Purifier Heater

For a vacuum company, Dyson can sometimes feel like nerd church. Its devices are a…

2 February 2026
News

The Tech Elites in the Epstein Files

The Tech Elites in the Epstein Files

“I had very little correspondence with Epstein and declined repeated invitations to go to his island or fly on his ‘Lolita Express,’ but was well aware that some email correspondence…

News Room 2 February 2026

Your may also like!

Amazon’s desk-friendly Echo Show 8 is down to its lowest price ever
News

Amazon’s desk-friendly Echo Show 8 is down to its lowest price ever

News Room 2 February 2026
IGN Fan Fest returns in February, featuring exclusive reveals for Lego Batman and 007 First Light
Gaming

IGN Fan Fest returns in February, featuring exclusive reveals for Lego Batman and 007 First Light

News Room 2 February 2026
Our Favorite Soundbar for Most People Is  Off
News

Our Favorite Soundbar for Most People Is $50 Off

News Room 2 February 2026
Raspberry Pi is raising prices again as memory shortages continue
News

Raspberry Pi is raising prices again as memory shortages continue

News Room 2 February 2026

Our website stores cookies on your computer. They allow us to remember you and help personalize your experience with our site.

Read our privacy policy for more information.

Quick Links

  • Subscribe
  • Privacy Policy
  • Contact
  • Terms of Use
Advertise with us

Socials

Follow US
Welcome Back!

Sign in to your account

Lost your password?