Apparently a state-sponsored group was using Notepad++ update functionality to infect targeted people.

"According to the former hosting provider, the shared hosting server was compromised until September 2, 2025. Even after losing server access, attackers maintained credentials to internal services until December 2, 2025, which allowed them to continue redirecting Notepad++ update traffic to malicious servers."

source: notepad-plus-plus.org/news/hij

0

If you have a fediverse account, you can quote this note from your own instance. Search https://infosec.exchange/users/harrysintonen/statuses/116000080834789498 on your instance and quote it. (Note that quoting is not supported in Mastodon.)