First Published 3 Feb 2026

My thanks to Peter Bryant for alerting all members of the UK Access User Group of this issue earlier today.

The free open source Notepad++ text editor has been a very popular utility for around 20 years and is downloaded about 80,000 times each day.

However, an article published on 2 Feb at the HackingPassion.com website raises important issues that should concern all Notepad++ users: Notepad++ Supply Chain Attack Full Story

If you are a Notepad++ user, please read the full article to understand how these issues affect you!


TLDR: In summary:
•   Notepad++ delivered malware via a compromised update system from June to Dec 2025
•   Notepad++ itself was not hacked. However, it used a shared hosting provider which was intercepted so that updates were re-routed to malicious files on another server
•   The malware placed a file called AutoUpdater.exe in the Temp folder
     This ran a series of standard Windows commands to obtain information about network connections, hardware, running processes and users
•   The hackers exploited 3 security weaknesses: a self-signed certificate, no validation of certification and shared hosting.
•   All of these have now been addressed via a new hosting provider, improved security, certificate verification and signature checks

As a matter of urgency, all Notepad++ users should (as a minimum):
•   check for suspicious activity by its updater gup.exe and look for files in the temp folder called Autoupdater.exe or update.exe, neither of which are created by Notepad++
•   uninstall old versions of Notepad++ and reinstall version 8.8.9 or later from the official website. Do NOT trust the built-in updater on older versions as it may have been hacked
•   remove the old self signed certificate if it was ever installed

Now, please read the full article if you haven't already done so.



Feedback

Please use the E-Mail button in the contact form below to let me know whether you found this article useful or if you have any questions.

Please also consider making a donation towards the costs of maintaining this website. Thank you



Colin Riddington           Mendip Data Systems                 Last Updated 3 Feb 2026



Return to Access Blog Page




Return to Top