MIT TRACE

MIT CTL Logo
Back to Main Dashboard

Notepad++ update infrastructure compromise enables targeted malicious software delivery

A compromise affecting the official hosting infrastructure used by Notepad++ allowed attackers to intercept update traffic and selectively redirect users to attacker-controlled infrastructure between June and December 2025. Unit 42 found that the attackers breached the shared hosting provider environment and served malicious update manifests to selected targets, with infection chains delivering Cobalt Strike and the Chrysalis backdoor. The compromise occurred at the hosting-provider level rather than through vulnerabilities in the Notepad++ source code, but it abused the legitimate Notepad++ update channel to reach downstream users. Unit 42 attributed the activity to LOTUS BLOSSOM.

70

Estimated severity

70 / 100

89

Source reliability

89 / 100

Approximate Date

02/02/2026

Targeted Company

NOTEPAD++

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

No information

Geographic Impact

Country Targeted Company

Country visual unavailable

No information

Other Affected Countries

No other affected countries reported

Target country

No information

Affected countries

No information

Impacted regions

No information

Operational Impact

Duration

No information

Financial impact (USD M)

No information

Impact types

Supply chain data integrity impact

Affected sectors

Technology & IT Services

Affected departments

Information Technology

Attack Profile

Attack types

Software supply chain compromiseSoftware update compromiseThird-party or partner compromiseMalware

Attributed threat actors

LOTUS BLOSSOM

Sources

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.