Rapid7 dropped a write-up on the Notepad++ update-chain abuse and - finally - it comes with real IOCs - update.exe downloaded ...
Rapid7 links China-linked Lotus Blossom to a 2025 Notepad++ hosting breach that delivered the Chrysalis backdoor via hijacked updates, fixed in v8.8.9 ...
Time to use something simpler!
Turns out Windows is fast when you stop using the Start menu ...
The hosting provider's compromise allowed attackers to deliver malware through tainted software updates for six months.
A true lose/lose situation.
Notepad++ update servers were compromised for 6 months in 2025. Learn how the Chrysalis backdoor targeted users and why you must manually update to version 8.9.1 now.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results