Rapid7 links China-linked Lotus Blossom to a 2025 Notepad++ hosting breach that delivered the Chrysalis backdoor via hijacked ...
State-sponsored threat actors compromised the popular code editor's hosting provider to redirect targeted users to malicious ...
The hosting provider's compromise allowed attackers to deliver malware through tainted software updates for six months.
The attacks came from a third-party and not from the Notepad++ team.
The popular Notepad alternative was hijacked by bad actors for several months in 2025, but the latest update appears to solve the issue.