By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Notepad++ Fixes Hijacked Update Mechanism Used to Deliver Targeted Malware
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > Notepad++ Fixes Hijacked Update Mechanism Used to Deliver Targeted Malware
Computing

Notepad++ Fixes Hijacked Update Mechanism Used to Deliver Targeted Malware

News Room
Last updated: 2026/02/18 at 4:07 AM
News Room Published 18 February 2026
Share
Notepad++ Fixes Hijacked Update Mechanism Used to Deliver Targeted Malware
SHARE

Ravie LakshmananFeb 18, 2026Vulnerability / Application Security

Notepad++ has released a security fix to plug gaps that were exploited by an advanced threat actor from China to hijack the software update mechanism to selectively deliver malware to targets of interest.

The version 8.9.2 update incorporates what maintainer Don Ho calls a “double lock” design that aims to make the update process “robust and effectively unexploitable.” This includes verification of the signed installer downloaded from GitHub (implemented in version 8.8.9 and later), as well as the newly added verification of the signed XML returned by the update server at notepad-plus-plus[.]org.

In addition to these enhancements, security-focused changes have been introduced to WinGUp, the auto-updater component –

  • Removal of libcurl.dll to eliminate DLL side-loading risk
  • Removal of two unsecured cURL SSL options: CURLSSLOPT_ALLOW_BEAST and CURLSSLOPT_NO_REVOKE
  • Restriction of plugin management execution to programs signed with the same certificate as WinGUp

The update also addresses a high-severity vulnerability (CVE-2026-25926, CVSS score: 7.3) that could result in arbitrary code execution in the context of the running application.

“An Unsafe Search Path vulnerability (CWE-426) exists when launching Windows Explorer without an absolute executable path,” Ho said. “This may allow execution of a malicious explorer.exe if an attacker can control the process working directory. Under certain conditions, this could lead to arbitrary code execution in the context of the running application.”

The development comes weeks after Notepad++ disclosed that a breach at the hosting provider level enabled threat actors to hijack update traffic starting June 2025 and redirect requests from certain users to malicious servers to serve a poisoned update. The issue was detected in early December 2025.

According to Rapid7 and Kaspersky, the tampered updates enabled the attackers to deliver a previously undocumented backdoor dubbed Chrysalis. The supply chain incident, tracked under the CVE identifier CVE-2025-15556 (CVSS score: 7.7), has been attributed to a China-nexus hacking group called Lotus Panda.

Notepad++ users are recommended to update to version 8.9.2, and make sure that the installers are downloaded from the official domain.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article 10 stunning watches that celebrate the Year of the Fire Horse | Stuff 10 stunning watches that celebrate the Year of the Fire Horse | Stuff
Next Article Defence and education see big gains in public sector IT spend, Tussell report finds | Computer Weekly Defence and education see big gains in public sector IT spend, Tussell report finds | Computer Weekly
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Apple Music Connect is reborn as a marketing tool for the music industry
Apple Music Connect is reborn as a marketing tool for the music industry
News
Dell RecoverPoint for VMs Zero-Day CVE-2026-22769 Exploited Since Mid-2024
Dell RecoverPoint for VMs Zero-Day CVE-2026-22769 Exploited Since Mid-2024
Computing
that his boat was too
that his boat was too
Mobile
After layoffs, a key revelation about Highguard’s financing
After layoffs, a key revelation about Highguard’s financing
Mobile

You Might also Like

Dell RecoverPoint for VMs Zero-Day CVE-2026-22769 Exploited Since Mid-2024
Computing

Dell RecoverPoint for VMs Zero-Day CVE-2026-22769 Exploited Since Mid-2024

7 Min Read
Apple M3 With Asahi Linux Continues Making Progress, No ETA Yet For Shipping
Computing

Apple M3 With Asahi Linux Continues Making Progress, No ETA Yet For Shipping

3 Min Read
Foxconn Zhengzhou hires 50,000 workers in two weeks as iPhone 16 series stock may reach 95 million units · TechNode
Computing

Foxconn Zhengzhou hires 50,000 workers in two weeks as iPhone 16 series stock may reach 95 million units · TechNode

1 Min Read
How to Get Followers on Threads in 2025 (+ Brand Inspo)
Computing

How to Get Followers on Threads in 2025 (+ Brand Inspo)

4 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?