Country visual unavailable
No information
A compromise affecting the official hosting infrastructure used by Notepad++ allowed attackers to intercept update traffic and selectively redirect users to attacker-controlled infrastructure between June and December 2025. Unit 42 found that the attackers breached the shared hosting provider environment and served malicious update manifests to selected targets, with infection chains delivering Cobalt Strike and the Chrysalis backdoor. The compromise occurred at the hosting-provider level rather than through vulnerabilities in the Notepad++ source code, but it abused the legitimate Notepad++ update channel to reach downstream users. Unit 42 attributed the activity to LOTUS BLOSSOM.
Estimated severity
70 / 100
Source reliability
89 / 100
Approximate Date
02/02/2026
Targeted Company
NOTEPAD++
Distribution & Fulfillment
Procurement & Sourcing
Production & Manufacturing
Sales (Retail & Ecommerce)
Warehousing
Service Delivery
Unrecognized Impact
Supply Chain Relations
No information
Country visual unavailable
No information
No other affected countries reported
Target country
No information
Affected countries
No information
Impacted regions
No information
Duration
No information
Financial impact (USD M)
No information
Impact types
Affected sectors
Affected departments
Attack types
Attributed threat actors
Incident Sources
Please rotate your phone