Close Menu
Daily Guardian
  • Home
  • News
  • Politics
  • Business
  • Entertainment
  • Lifestyle
  • Health
  • Sports
  • Technology
  • Climate
  • Auto
  • Travel
  • Web Stories
What's On

Integra LifeSciences Unveils New Real-World Evidence Highlighting PriMatrix® Utilization

April 7, 2026

Bitdeer Launches SEALMINER A4 Series Bitcoin Mining Rigs, Achieves a Power Efficiency of 9.45 J/TH

April 7, 2026

Trump says ‘a whole civilization will die tonight’ as Iran deadline looms

April 7, 2026

AFX launches high-performance Sovereign L1 testnet: A community-first revolution in on-chain derivatives

April 7, 2026

Agriculture & Farm Equipment Industry Forecast Report 2026-2032: Key Opportunities in Electrification, Autonomy, Data-driven Services, and Modularity

April 7, 2026
Facebook X (Twitter) Instagram
Finance Pro
Facebook X (Twitter) Instagram
Daily Guardian
Subscribe
  • Home
  • News
  • Politics
  • Business
  • Entertainment
  • Lifestyle
  • Health
  • Sports
  • Technology
  • Climate
  • Auto
  • Travel
  • Web Stories
Daily Guardian
Home » Notepad++ updates got hijacked for months and could have spied for China
Technology

Notepad++ updates got hijacked for months and could have spied for China

By News RoomFebruary 2, 20262 Mins Read
Notepad++ updates got hijacked for months and could have spied for China
Share
Facebook Twitter LinkedIn Pinterest Email

Users of the text and code editor Notepad++ may have unknowingly downloaded a malicious update for the app after its shared hosting servers were hijacked last year. On Monday, the app’s developer, Don Ho, posted an update on the attack with more details, including that the hackers were “likely a Chinese state-sponsored group” and that the app’s servers were vulnerable for roughly six months from June through December 2nd, 2025.

The post explains that the hijacking occurred on the app’s unnamed, now-former hosting provider’s end, stating that “Traffic from certain targeted users was selectively redirected to attacker-controlled served malicious update manifests.” When victims were redirected, their app update could be replaced with a malicious executable that, according to independent cybersecurity expert Kevin Beaumont, may have given the hackers remote access to a victim’s keyboard.

Don Ho’s post also adds that the attack involved “highly selective targeting” in terms of the victims it redirected away from the legitimate Notepad++ website. Kevin Beaumont noted that the victims he spoke with “are [organizations] with interests in East Asia.” So, while this is a serious security vulnerability, it’s possible that the hackers were busy watching specific people instead of just anyone.

The developer did not specify when they became aware of the attack, but said that “all attacker access was definitively terminated” by December 2nd. The Notepad++ updater has been updated itself with stronger security measures to check for tampering and verify that updates are legitimate.

Notepad++ users should make sure they are on at least version 8.8.9, which addressed the vulnerabilities from the hijacking attack, and they should probably download that version directly from the Notepad++ website. Additionally, Kevin Beaumont suggested users double-check that they’re not using an unofficial version of Notepad++, keep a close eye on activity from “gup.exe,” the app’s updater, and check for a suspicious “update.exe” or “AutoUpdater.exe” file in their TEMP folder.

Notably, Don Ho, the developer of Notepad++, criticized the Chinese government in a 2019 app update. He called that version the “Free Uyghur” edition, and told The Verge at the time that his website had faced DDoS attacks in response.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Keep Reading

A wild, wide foldable iPhone dummy emerges amid rumors of a delay

DJI’s Mic Mini records clear audio on the go, and it’s on sale for $60

Cisco CEO Chuck Robbins wants data centers in space

Samsung’s Galaxy S27 ‘Pro’ could squeeze in between the Ultra and Plus phones

Logitech’s haptics-enhanced MX Master 4 mouse is on sale for under $100

Can AI responses be influenced? The SEO industry is trying

Suno is a music copyright nightmare capable of pumping out AI cover slop

The full origins of Alexa and the Amazon Echo

I let Gemini in Google Maps plan my day and it went surprisingly well

Editors Picks

Bitdeer Launches SEALMINER A4 Series Bitcoin Mining Rigs, Achieves a Power Efficiency of 9.45 J/TH

April 7, 2026

Trump says ‘a whole civilization will die tonight’ as Iran deadline looms

April 7, 2026

AFX launches high-performance Sovereign L1 testnet: A community-first revolution in on-chain derivatives

April 7, 2026

Agriculture & Farm Equipment Industry Forecast Report 2026-2032: Key Opportunities in Electrification, Autonomy, Data-driven Services, and Modularity

April 7, 2026

Latest News

Deep Isolation Nuclear Selected for ARPA-E SCALEUP Award to Advance Universal Canister System and Deep Borehole Disposal

April 7, 2026

Emergent BioSolutions Launches New NARCAN® Nasal Spray Carrying Case and Multipacks Alongside College Campus Outreach to Expand Opioid Overdose Preparedness

April 7, 2026

From Checks to Systems: Regula Recognized Across Key Layers of Identity Verification in 2026 Cybersecurity Excellence Awards

April 7, 2026
Facebook X (Twitter) Pinterest TikTok Instagram
© 2026 Daily Guardian Canada. All Rights Reserved.
  • Privacy Policy
  • Terms
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.

Go to mobile version