First Published 3 Feb 2026
My thanks to Peter Bryant for alerting all members of the UK Access User Group of this issue earlier today.
The free open source Notepad++ text editor has been a very popular utility for around 20 years and is downloaded about 80,000 times each day.
However, an article published on 2 Feb at the HackingPassion.com website raises important issues that should concern all Notepad++ users: Notepad++ Supply Chain Attack Full Story
If you are a Notepad++ user, please read the full article to understand how these issues affect you!
TLDR: In summary:
• Notepad++ delivered malware via a compromised update system from June to Dec 2025
• Notepad++ itself was not hacked. However, it used a shared hosting provider which was intercepted so that updates were re-routed to malicious files on another server
• The malware placed a file called AutoUpdater.exe in the Temp folder
This ran a series of standard Windows commands to obtain information about network connections, hardware, running processes and users
• The hackers exploited 3 security weaknesses: a self-signed certificate, no validation of certification and shared hosting.
• All of these have now been addressed via a new hosting provider, improved security, certificate verification and signature checks
As a matter of urgency, all Notepad++ users should (as a minimum):
• check for suspicious activity by its updater gup.exe and look for files in the temp folder called Autoupdater.exe or update.exe, neither of which are created by Notepad++
• uninstall old versions of Notepad++ and reinstall version 8.8.9 or later from the official website. Do NOT trust the built-in updater on older versions as it may have been hacked
• remove the old self signed certificate if it was ever installed
Now, please read the full article if you haven't already done so.
Feedback
Please use the E-Mail button in the contact form below to let me know whether you found this article useful or if you have any questions.
Please also consider making a donation towards the costs of maintaining this website. Thank you
Colin Riddington Mendip Data Systems Last Updated 3 Feb 2026
|
Return to Access Blog Page
|
Return to Top
|