The Notepad++ Update Supply Chain Attack

Updated 5 Oct 2026 · Incident date 1 Jun 2025 · vendor binary

PackageNotepad++ 8.8.2 through 8.8.9 - trojanized updates delivered via the WinGUP updater; fixed in 8.9.1
FileAutoUpdater.exe, spawned by GUP.exe from the malicious NSIS package

In 2025, attackers hijacked update traffic for Notepad++ and delivered trojanized updates through the WinGUp updater. ThreatLocker lists the affected versions as 8.8.2 through 8.8.9. The fixed version is 8.9.1.

The Notepad++ installer files were not the target. The attackers took over the route between the updater and the update server.

What happened

Attackers redirected requests from the Notepad++ updater to servers that they controlled. Unit 42 reports that the group compromised the shared hosting infrastructure behind the update server, so it was able to intercept and redirect that traffic. Older WinGUp versions did not check the signature of the downloaded installer.

ThreatLocker reports that the compromise ran from June 2025 to 2 December 2025, and that it was disclosed on 2 February 2026. During a bad update, WinGUp (GUP.exe) started a program named AutoUpdater.exe. This program collected network connections, host details, running processes and users. It wrote them to a file named a.txt and sent it with curl.exe to temp[.]sh.

Unit 42 describes two kinds of payload. One was a Cobalt Strike Beacon delivered with a malicious Lua script inside an NSIS installer. The other was the Chrysalis backdoor, loaded by DLL side-loading from a Bitdefender component, BluetoothService.exe, with a malicious log.dll. Unit 42 attributes the activity to Lotus Blossom, a state-sponsored group. Targets were mainly in Southeast Asia, in government, telecommunications and critical infrastructure.

Vigilance compares the version you trust with the new one. An update that starts running new programs is the kind of change it reports. See the scan block below.

Affected versions

The sources differ on the exact first and last affected build. Treat any update made through WinGUp from June to December 2025 as suspect. The attack hit only machines that the attackers chose, so most users did not receive a bad file.

Indicators of compromise

How to check

Check the installed version and look for the files that the attack used. Run this in PowerShell.

(Get-Item "$env:ProgramFiles\Notepad++\notepad++.exe").VersionInfo.ProductVersion; Get-ChildItem $env:TEMP -Recurse -Include AutoUpdater.exe,log.dll,a.txt -ErrorAction SilentlyContinue

If Notepad++ sits in another folder, change the path. Search proxy and DNS logs for the domains above. Search endpoint logs for GUP.exe starting curl.exe.

What to do now

  1. Install Notepad++ 8.9.1 or later. Download it by hand from the official site instead of using the old updater.
  2. Search machines and logs for the indicators above.
  3. If you find a hit, isolate the host and review it. Reinstall it if a backdoor ran.
  4. Block the domains and IP addresses.
  5. Use application allowlisting so that unknown programs cannot start from temporary folders.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old Notepad-prev --new Notepad-current
files scanned: 41 (1 Added)

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

NEW FILE   AutoUpdater.exe
           It downloads from the internet.

Frequently asked questions

Which Notepad++ versions received trojanized updates?

ThreatLocker lists Notepad++ 8.8.2 through 8.8.9, delivered through the WinGUp updater. Version 8.9.1 is the fixed release.

How were the Notepad++ updates hijacked?

Unit 42 reports that attackers compromised the shared hosting behind the update server and redirected updater traffic. Older WinGUp versions did not verify the downloaded installer.

Sources

  1. unit42.paloaltonetworks.com/notepad-infrastructure-compromise/
  2. threatlocker.com/blog/notepad-supply-chain-compromise-trojanized-updates-used-in-suspected-nation-state-attack

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free