Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Supply Chain Attack Abused Notepad++ Update Infrastructure to Deliver Targeted Malware

On Mon, Feb 2, 2026, Notepad++ developers disclosed a significant security breach impacting their update infrastructure.

On Mon, Feb 2, 2026, Notepad++ developers disclosed a significant security breach impacting their update infrastructure.

The text editor, extensively utilized by developers worldwide, was subjected to a sophisticated supply chain attack that remained undetected for several months.

According to the official statement, attackers obtained unauthorized access through a hosting provider-level incident occurring between June and September 2025. This allowed them persistent access to internal services until December 2025.

The attack campaign exhibited a high level of operational sophistication. Threat actors continually rotated command and control server addresses, downloaders, and final payloads over four months, from July to October 2025.

This persistent modification of attack infrastructure presented significant challenges for security teams in detecting and analyzing the threat.

The compromised update mechanism specifically targeted approximately a dozen machines belonging to individuals in Vietnam, El Salvador, and Australia, in addition to organizations in the Philippines and an IT service provider in Vietnam.

Securelist analysts identified three distinct infection chains during their investigation, each showcasing unique technical characteristics and evasion techniques.

On Mon, Feb 2, 2026, Notepad++ developers disclosed a significant security breach impacting their update infrastructure.
Eleanor Tate · Thehackingpost

The attackers utilized multiple frameworks, including Metasploit downloaders and Cobalt Strike Beacon payloads, while deploying the custom Chrysalis backdoor in later stages.

Despite the variety of malicious payloads observed throughout the campaign, Kaspersky security solutions successfully blocked the identified attacks as they occurred.

The first infection chain emerged in late July 2025. Attackers distributed a malicious NSIS installer through the compromised update infrastructure.

When executed by the legitimate Notepad++ updater process, the malicious update.exe file immediately transmitted system reconnaissance information to attacker-controlled servers via the temp.sh file hosting service.

This activity involved executing shell commands to collect username, running processes, system information, and network connections before uploading results through precisely crafted curl commands.

Instead of utilizing the commonly used DLL sideloading technique, attackers exploited an older vulnerability in ProShow software dating back to the early 2010s.

Advertisement

This approach aided in evading modern detection systems that heavily monitor DLL sideloading activities.

The exploit payload comprised two shellcodes. The first served as padding to confuse automated analysis systems, while the second decrypted a Metasploit downloader that retrieved Cobalt Strike Beacon shellcode from remote servers.

Security teams can detect this threat by monitoring for NSIS installer deployments, checking for %localappdata%\Temp\ns.tmp directory creation logs.

Organizations should also inspect network traffic for unusual DNS resolutions to the temp.sh domain and examine system logs for reconnaissance commands like whoami, tasklist, systeminfo, and netstat.

Implementing behavioral detection rules for registry autorun modifications and monitoring connections to Living-Off-the-Land C2 services provides additional defense layers against similar supply chain compromises.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories