The Notepad++ website was hijacked by 'malicious actors' last year and security researchers are picking through the wreckage

The Notepad++ logo, depicting a green frog on a yellow pencil
(Image credit: Notepad++)

Popular open source text editor Notepad++ experienced a significant security breach last year, and now its developer has given an update regarding the attack.

It's believed that, between June and November 10/December 2, 2025 (independent security experts and its hosting provider disagree on the exact timings), a shared hosting server was compromised, allowing attackers to redirect Notepad++ update traffic to malicious servers.

Hacker, IT and person with code on computer, programming and phishing scam with malware or virus.

(Image credit: seksan Mongkhonkhamsao @ Getty Images)

According to cybersecurity firm Rapid7, the attack can be contributed to Chinese APT group Lotus Blossom, a threat actor that has been known to perform "targeted espionage campaigns" primarily impacting organisations across Southeast Asia and Central America. The custom backdoor used in the attack has since been dubbed "Chrysalis", and explaining its methodology is where I start to get lost, so I'll quote directly from the Rapid7 report instead:

"Its wide array of capabilities indicates it is a sophisticated and permanent tool, not a simple throwaway utility. It uses legitimate binaries to sideload a crafted DLL with a generic name, which makes simple filename-based detection unreliable.

"It relies on custom API hashing in both the loader and the main module, each with its own resolution logic. This is paired with layered obfuscation and a fairly structured approach to C2 communication."

Security Padlock

(Image credit: Pixabay)

Of course, of course. However, Rapid7's main concern appears to be what Chrysalis, and other tools and methods used in the attack, says about Lotus Blossom's newfound capabilities:

"While the group continues to rely on proven techniques like DLL sideloading and service persistence, their multi-layered shellcode loader and integration of undocumented system calls (NtQuerySystemInformation) mark a clear shift toward more resilient and stealth tradecraft," says the firm.

"This demonstrates that Lotus Blossom is actively updating their playbook to stay ahead of modern detection."

Gulp. So, while the Notepad++ developer has since switched to a different hosting provider (with what are described as "significantly stronger security practices"), it seems that Lotus Blossom is gaining strength—and some hosting providers are falling victim to its modern methods. Sleep tight, website.

Secretlab Titan Evo gaming chair in Royal colouring, on a white background
Best PC gaming kit 2026

1. Best gaming chair: Secretlab Titan Evo

2. Best gaming desk: Secretlab Magnus Pro XL

3. Best gaming headset: Razer BlackShark V3

4. Best gaming keyboard: Asus ROG Strix Scope II 96 Wireless

5. Best gaming mouse: Razer DeathAdder V4 Pro

6. Best PC controller:

Andy Edser
Hardware Writer

Andy built his first gaming PC at the tender age of 12, when IDE cables were a thing and high resolution wasn't—and he hasn't stopped since. Now working as a hardware writer for PC Gamer, Andy spends his time jumping around the world attending product launches and trade shows, all the while reviewing every bit of PC gaming hardware he can get his hands on. You name it, if it's interesting hardware he'll write words about it, with opinions and everything.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.