Close Menu
TechTost
  • AI
  • Apps
  • Crypto
  • Fintech
  • Hardware
  • Media & Entertainment
  • Security
  • Startups
  • Transportation
  • Venture
  • Recommended Essentials
What's Hot

Notepad++ says Chinese government hackers hijacked its software updates for months

Carbon Robotics built an AI model that detects and recognizes plants

Waymo raises $16 billion to scale robotaxi fleet globally

Facebook X (Twitter) Instagram
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
Facebook X (Twitter) Instagram
TechTost
Subscribe Now
  • AI

    Elon Musk’s SpaceX officially acquires Elon Musk’s xAI, with plan to build data centers in space

    2 February 2026

    These AI note taking devices can help you record and transcribe your meetings

    2 February 2026

    Indonesia ‘conditionally’ lifts Grok ban

    1 February 2026

    OpenClaw’s AI assistants are now building their own social network

    1 February 2026

    Nvidia CEO refutes report that his company’s $100 billion OpenAI investment has stalled

    31 January 2026
  • Apps

    Adobe Animate is shutting down as the company focuses on artificial intelligence

    2 February 2026

    TikTok says its services are being restored after the outage

    2 February 2026

    Apple tells Patreon to move creators to in-app purchases for subscriptions by November

    1 February 2026

    Chrome takes on AI browsers with tighter Gemini integration, agent-like features for autonomous tasks

    1 February 2026

    WhatsApp will now charge for AI chatbots to operate in Italy

    31 January 2026
  • Crypto

    Hackers stole over $2.7 billion in crypto in 2025, data shows

    23 December 2025

    New report examines how David Sachs may benefit from Trump administration role

    1 December 2025

    Why Benchmark Made a Rare Crypto Bet on Trading App Fomo, with $17M Series A

    6 November 2025

    Solana co-founder Anatoly Yakovenko is a big fan of agentic coding

    30 October 2025

    MoviePass opens Mogul fantasy league game to the public

    29 October 2025
  • Fintech

    How Sequoia-backed Ethos went public while rivals lagged behind

    30 January 2026

    5 days left for TechCrunch Disrupt 2026 +1 pass with 50%

    26 January 2026

    50% off +1 ends | TechCrunch

    23 January 2026

    Capital One acquires Brex for a steep discount to its valuation, but early believers are laughing all the way to the bank

    23 January 2026

    Tiger Global and Microsoft will fully exit Walmart-backed PhonePe through its IPO

    22 January 2026
  • Hardware

    Ring brings “Search Party” feature for finding lost dogs to non-Ring camera owners

    2 February 2026

    India offers zero taxes till 2047 to attract global AI workloads

    1 February 2026

    Microsoft won’t stop buying AI chips from Nvidia, AMD even after its own is released, says Nadella

    30 January 2026

    The iPhone just had its best quarter ever

    30 January 2026

    Snap is serious about specs, spinning off AR glasses into a standalone company

    28 January 2026
  • Media & Entertainment

    Amazon’s ‘Melania’ Documentary Makes $7M in Opening Weekend

    2 February 2026

    OnlyFans is considering selling a majority stake to Architect Capital

    31 January 2026

    Last 24 hours to get 50% off +1 pass for Disrupt 2026 | TechCrunch

    30 January 2026

    Disrupt 2026: +1 cards are almost gone with only 3 days left

    28 January 2026

    Sci-fi writers, Comic-Con say goodbye to artificial intelligence

    26 January 2026
  • Security

    Notepad++ says Chinese government hackers hijacked its software updates for months

    3 February 2026

    Russian hackers breached Poland’s power grid thanks to poor security, report says

    31 January 2026

    Whistleblower Told FBI Jeffrey Epstein Had ‘Personal Hacker’

    31 January 2026

    Fintech firm Marquis blames hack on firewall provider SonicWall for data breach

    30 January 2026

    Apple’s new iPhone and iPad security feature restricts mobile networks from collecting accurate location data

    29 January 2026
  • Startups

    Carbon Robotics built an AI model that detects and recognizes plants

    3 February 2026

    Meet the new European unicorns of 2026

    1 February 2026

    HomeBoost’s app will show you where you can save money on your utility bills

    1 February 2026

    Qualcomm backs SpotDraft to scale AI with on-device deal doubling valuation to $400 million

    31 January 2026

    Redwood Lands Google for $425M Series E as AI Power Needs Grow

    31 January 2026
  • Transportation

    Waymo raises $16 billion to scale robotaxi fleet globally

    3 February 2026

    The San Francisco Police Department is investigating the Zoox collision with a parked car

    2 February 2026

    TechCrunch Mobility: Tesla’s big rebranding

    2 February 2026

    Luminar sale approved despite last-minute mystery bid

    1 February 2026

    Tesla profits down 46% in 2025

    1 February 2026
  • Venture

    Two Stanford students launch $2 million startup accelerator for students nationwide

    3 February 2026

    a16z contributor Kofi Ampadu will be leaving permanently after the TxO program is discontinued

    31 January 2026

    Reid Hoffman urges Silicon Valley leaders to stop bending the knee to President Trump

    31 January 2026

    VC 2150 raises €210 million to solve cities’ climate challenges

    27 January 2026

    Obvious Ventures lands fund five with a 360-degree view of planetary, human and financial health

    27 January 2026
  • Recommended Essentials
TechTost
You are at:Home»Security»Notepad++ says Chinese government hackers hijacked its software updates for months
Security

Notepad++ says Chinese government hackers hijacked its software updates for months

techtost.comBy techtost.com3 February 202603 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
Notepad++ Says Chinese Government Hackers Hijacked Its Software Updates For
Share
Facebook Twitter LinkedIn Pinterest Email

The developer of the popular open-source text editor Notepad++ has confirmed that hackers took over the software to deliver malicious updates to users over several months in 2025.

In one blog post Posted on Monday, Notepad++ developer Don Ho said the cyberattack was likely carried out by hackers associated with the Chinese government between June and December 2025, citing multiple analyzes by security experts who looked at malware payloads and attack patterns. Ho said this “would explain the highly selective targeting” seen during the campaign.

Rapid7, which investigated the incidentattributed the hacking to Lotus Blossom, a longtime espionage group known to work for China, and said the hacks targeted government, telecommunications, aviation, critical infrastructure and media sectors.

Notepad++ is one of the longest-running open source projects, spanning more than two decades and counting at least tens of millions of downloads to date, including by employees in organizations around the world.

According to Kevin Beaumont, a security researcher who first discovered the cyber attack and wrote up his findings In December, hackers breached a small number of organizations “with interests in East Asia” after someone unwittingly used an altered version of the popular software. Beaumont said the hackers were able to gain “hands-on” access to victims’ computers running compromised versions of Notepad++.

Ho said the “exact technical mechanism” of how the hackers broke into his servers remains under investigation, but provided some details about how the attack went down.

In the blog, Ho said that the Notepad++ website was hosted on a shared hosting server. The attackers “specifically targeted” the Notepad++ web domain with the aim of exploiting a bug in the software to redirect some users to a malicious server run by the hackers. This allowed hackers to deliver malicious updates to some users who had requested a software update, until The bug was fixed in November and the hackers’ access was terminated in early December.

“We have logs showing that the bad actor attempted to re-exploit one of the patched vulnerabilities, however, the attempt did not fail after the patch was applied,” Ho wrote.

In an email, Ho told TechCrunch that his hosting provider confirmed that its shared server had been hacked, but that the provider did not say how the hackers broke in in the first place.

Ho apologized for the incident and urged users to download it latest version of its software, which contains a fix for the bug.

The cyberattack targeting Notepad++ users is somewhat reminiscent of the 2019-2020 cyberattack affecting customers of SolarWinds, a software company that makes IT and network management tools for large Fortune 500 organizations, including government agencies. Russian government spies hacked into the company’s servers and secretly installed a backdoor in its software, allowing Russian spies to access data on those customers’ networks once the update was released.

The SolarWinds breach affected several government agencies, including Homeland Security and the Departments of Commerce, Energy, Justice and State.

Updated with response from Ho and additional details from Rapid7.

China Chinese cyber security government hackers hijacked months Notepad ++ open source software SolarWinds updates
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleCarbon Robotics built an AI model that detects and recognizes plants
bhanuprakash.cg
techtost.com
  • Website

Related Posts

OpenClaw’s AI assistants are now building their own social network

1 February 2026

Russian hackers breached Poland’s power grid thanks to poor security, report says

31 January 2026

Whistleblower Told FBI Jeffrey Epstein Had ‘Personal Hacker’

31 January 2026
Add A Comment

Leave A Reply Cancel Reply

Don't Miss

Notepad++ says Chinese government hackers hijacked its software updates for months

3 February 2026

Carbon Robotics built an AI model that detects and recognizes plants

3 February 2026

Waymo raises $16 billion to scale robotaxi fleet globally

3 February 2026
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Fintech

How Sequoia-backed Ethos went public while rivals lagged behind

30 January 2026

5 days left for TechCrunch Disrupt 2026 +1 pass with 50%

26 January 2026

50% off +1 ends | TechCrunch

23 January 2026
Startups

Carbon Robotics built an AI model that detects and recognizes plants

Meet the new European unicorns of 2026

HomeBoost’s app will show you where you can save money on your utility bills

© 2026 TechTost. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.