Jump to content

Recommended Posts

Posted

Link: Multiple Notepad++ Flaws Let Attackers Execute Arbitrary Code

 

Several Buffer Overflow vulnerabilities have been discovered in Notepad++ that can be exploited by threat actors for malicious purposes. The severities of these vulnerabilities vary from 5.5 (Medium) to 7.8 (High).

 

The vulnerabilities are based on heap buffer write overflow and heap buffer read overflow on some functions and libraries used by Notepad++ software, identified by Gitlab security researcher Jaroslav Lobačevski (@JarLob).

 

Notepad++ is an open-source C++-based source code editor that works in Microsoft x86, x64, and AArch64-based architectures. Notepad++ supports tabbed editing and allows working with multiple files in a single window. Don Ho developed it.

 

Notepad++ has not patched these vulnerabilities. However, according to their coordinated disclosure policy, GitLab published these vulnerabilities along with the proof-of-concept...

Posted

Notepad++ 8.5.7 released with fixes for four security vulnerabilities

 

Notepad++ version 8.5.7 has been released with fixes for multiple buffer overflow zero-days, with one marked as potentially leading to code execution by tricking users into opening specially crafted files.

 

https://notepad-plus-plus.org/news/v857-released-fix-security-issues

 

This release addresses 4 security issues (CVE-2023-40031, CVE-2023-40036, CVE-2023-40164 & CVE-2023-40166) and introduces several bug-fixes and new features.
  • 2 months later...
Posted

Link: Download Notepad++ v8.6: 20th-Year Anniversary | Notepad++

 

Notepad++ v8.6 new features & bug-fixes:

 

  1. Multi-edit is fully supported in Notepad++. (Fix #14266, #8203)
  2. Make multi-select background & caret colours customizable. (Fix #14302)
  3. Make session inaccessible files remembered (empty & read-only document as placeholder). (Fix #12079, #12744, #13696)
  4. Fix missing session invalid error for user session & enhance API NPPM_GETNBSESSIONFILES. (Fix #14228)
  5. Fix network shared files saving regression. (Fix #14300)
  6. Update Scintilla to v5.3.8 & Lexilla to v5.2.8. (Fix #13442, #14188, #14288)
  7. Fix docking panel crash due to messing up config.xml. (Fix bug report
  8. Fix invalid styler.xml making Notepad++ crash issue. (Fix #12101)
  9. Fix tab-closing crash by middle mouse button (unexpected mouse position). (Fix #14328)
  10. Fix 2 performance issues in Style Configurator. (Fix #14321)
  11. Add 3 line operation (delete, copy & cut) shortcuts. (Fix #14296)
  12. Display extra info in the status bar of Find/Replace dialog to avoid PEBKAC. (Fix #14307)
  13. Fix “Hide lines” command hiding unselected lines issue. (Fix #14166)
  14. Fix silent installer mode when Notepad++ is running issue. (Fix #10189, #10277, #22514, #14236, fix partially #8514)
  15. Fix Updater’s vulnerability (update cURL in WinGUp for fixing CVE-2023-38545). (Fix WinGUp issue #50)
  16. Fix incoherent behaviour of “Duplicate Current Line” menu command. (Fix #5298)
  17. Fix JSON5 not using JSON keywords. (Fix #14205)
  18. Fix empty message showing while cancelling session file saving dialog. (Fix #14235)

  • 1 month later...
Posted

Link: Download Notepad++ v8.6.1 | Notepad++

 

Notepad++ v8.6.1 new features & bug-fixes:

 

  1. Updated to Scintilla 5.4.1 & Lexilla 5.3.0. (Implement #14375)
  2. Fix a regression: the position in the previous session is now restored correctly in cloned document. (Fix #14164)
  3. Fix a regression: customized extension in Style Configurator is now saved correctly. (Fix #14437)
  4. Add an ability (disableLineCopyCutDelete.xml) to disable line copy/cut/delete when no selection is made. (Fix #14470, ref, ref))
  5. Add an ability (noColumnToMultiSelect.xml) to disable column mode to multi-select mode. (Fix #14464, ref)
  6. Fix deleting in column mode also delete an unexpected EOL. (Fix #14426)
  7. Fix hidden results of long lines for Search results with “Find in…” commands. (Fix #12023)
  8. Enhance Search-results by showing search options for “Find in…” commands. (Fix #14306)
  9. Fix an issue: replacements are no longer duplicated (the 2nd time in cloned document) for “Replace in Opened Docs”. (Fix #14505)
  10. Fix a regression to make F3 & Shift-F3 work again in Incremental Search. (Fix #14503)
  11. Add document tab navigation commands: “First tab” & “Last tab”. (Fix #14416)
  12. Add document tab commands: “Move to Start” & “Move to End” commands. (Fix #9525, #13982)
  13. 3 RTL new abilities: RTL per document, RTL per document remembered across the sessions & new attribute editZoneRTL=“no” in RTL localization files. (Fix #9665, #9950, #14385)
  14. Enhance the “-loadingTime” command line parameter. (Fix #14472)
  15. Enhance the performance: disable undo collection while loading a file. (Fix #14455)
  16. Sort language list in the Preferences dialog. (Fix #14245)
  17. Fix a visual glitch that occurred during multi-paste. (Fix #14410)
  18. Fix confusing memory allocation error message. (Fix #14418)
  19. Fix python wrong decorator attribute color. (Fix #5894)
  20. Fix file status in “other view” is not detected. (Fix #14225)
  21. Fix dropped file being opened in the wrong view. (Fix #14354)

  • 1 month later...
Posted

Link: Download Notepad++ v8.6.4 | Notepad++

 

Notepad++ v8.6.3 bug-fixes & enhancements:

 

  1. Restore multi-editing option & add “Column To Multi-editing” option on GUI. (Fix #14645)
  2. Make “copy/cut line while no selection” optional. (Fix #14638)
  3. Fix all open files lost after restarting as Admin to save a file. (Fix #14694)
  4. Fix “Replace All” crash & performance issue. (Fix #14630)
  5. Fix calltip crash due to the division by zero. (Fix #14664)
  6. Enhance Function List for Python to support “async def” & colons in argument list. (Fix #13908)
  7. Fix Copy/Cut/Paste issue in Vertical Edge text field in preferences dialog. (Fix #13874)
  8. Fix macro recording twice for some commands. (Fix #5217, #14634)
  9. Fix “Open File” command not working with TAB preceded. (Fix #14543)
  10. Add auto-completion keywords for PHP, JavaScript and CSS. (Fix #14635, #14705)

  • 8 months later...
Posted

Link: Celebrating 21 Years of Notepad++: The Legendary Journey of Our Favorite Text Editor - learnhub

 

Alright, folks, gather around because it’s story time about one of the most underrated yet indispensable tools in the digital world—Notepad++. This month marks the 21st anniversary of this amazing software, and that’s right, Notepad++ is finally legal to drink (if it were a person, of course). Can you believe it? 21 years of keeping developers, writers, and pretty much anyone who’s ever needed to write a chunk of text happy and efficient.

 

A Little Nostalgia: Where It All Began

 

Let’s rewind to 2003. It was a simpler time. YouTube didn’t even exist yet, the iPhone was still a distant dream, and social media was nowhere near what it is today. Somewhere in that digital wilderness, a passionate developer named Don Ho (no, not the Hawaiian singer) decided that the existing text editors were just not cutting it. He wanted something more powerful yet lightweight, a tool that respected a user’s CPU and RAM, unlike some bloated software out there. So, he started developing Notepad++, and on November 25th, 2003, the first version saw the light of day.

 

Fun fact: It’s built on Scintilla, a free source code editing component, and written in C++ for ultimate performance. Even back then, Notepad++ was all about being efficient, just like the developers who use it.

 

Why We Love It: The Features That Make It Special

 

So what makes Notepad++ so special that it’s still kicking after 21 years? The magic lies in its simplicity and, ironically, its complexity. It’s simple for those who need a straightforward, no-nonsense text editor, yet it offers complex features for hardcore developers who demand syntax highlighting, multi-document tabbing, and support for dozens of programming languages. It’s a tool that evolves with you.

 

Remember when auto-save was the most mind-blowing feature? Or how about that moment you discovered you could compare two files side-by-side? Yeah, those were “Whoa!” moments we never forget. And let’s not ignore the thousands of plugins that make your editing experience as smooth as a freshly oiled engine. Need to turn JSON into something readable? Boom, there’s a plugin for that. Want to FTP directly from your editor? Done. Notepad++ has been the Swiss Army knife of text editors, and we’ve all been better for it.

 

Through the Ups and Downs: The Drama and the Triumphs

 

Notepad++ has had its fair share of adventures over the years. In fact, it hasn’t shied away from taking a stand on social and political issues. One famous episode occurred in 2019, when Don Ho released a version called “Free Uyghur” to raise awareness about the situation in Xinjiang. This caused quite a stir and even got Notepad++ banned in some regions. It was a bold move, but it showed that this wasn’t just a piece of software; it was a platform for advocacy.

 

And let’s not forget about the challenges of keeping Notepad++ relevant in an era dominated by fancy IDEs like Visual Studio Code. Yet, even as tech trends come and go, Notepad++ continues to be beloved. It’s like the vinyl records of text editors—no matter how modern things get, there’s always something timeless about it.

 

The Secret Sauce: Community Love and Open-Source Spirit

 

What really makes Notepad++ extraordinary is its community. Being open-source means that countless developers have contributed to making it better, more secure, and more functional. This little editor that could has stayed alive and thriving for two decades, not because of a massive corporation backing it, but because of people like us who believed in its purpose.

 

Over the years, Notepad++ has received numerous awards, and rightfully so. From SourceForge Community Choice Awards to Lifehacker’s reader favorites, it’s a decorated veteran of the software world. But, you know, it’s not really about the awards. It’s about how many hours of work it has saved us. The late-night coding sessions where syntax highlighting kept our eyes from bleeding, or the way it smoothly handles massive files when other editors throw up their hands and crash.

 

Looking to the Future: What’s Next for Notepad++?

 

As Notepad++ steps into its 21st year, the future looks bright. Sure, there will be more trends, more changes in how we write and manage code, but Notepad++ will always have a place. Whether you’re a seasoned developer, a writer needing a distraction-free space, or just someone editing a config file, it’s there for you.

 

Who knows? Maybe one day it’ll have AI features, or perhaps it’ll integrate seamlessly with the tech of the future. But even if it doesn’t, we know it’ll always remain true to its roots: a fast, efficient, no-BS editor for everyone.

 

So here’s to you, Notepad++. Thanks for 21 incredible years. We can’t wait to see what you’ll do next!

  • Thanks 1
Posted

Link: Download Notepad++ v8.7.1 | Notepad++

 

Notepad++ v8.7.1 bug-fixes & enhancements:

 

  1. Update cURL in Notepad++ updater (WinGUp) for fixing cURL’s CVE-2024-7264 issue. (Fix #73)
  2. Fix opened network files hanging while the network disconnected. (Fix #4306, #6178, #8055, #11388, #12553, #15540)
  3. Fix not being able to open folder via cammand argument regression. (Fix #15645)
  4. Update to Scintilla 5.5.3 & Lexilla 5.4.1. (Fix #15228, #15368, #15650)
  5. Fix modified Find dialog status msg colors not being remembered throu sessions. (Fix #15724)
  6. Fix hanging issue while hiding lines. (Fix #15630)
  7. Make left behide hide line close marker removable. (Fix #15713)
  8. Fix Find dialog status bar wrong messaging (regression). (Fix #15662)
  9. Fix URL parsing issue with ‘?’ after ‘#’. (Fix #13583)
  10. Add “Close to system tray” ability. (Fix #4075, #11627)
  11. Add tab created time tooltip for new opened untitled tab. (Fix #15563)
  12. Improve GUI to avoid user confusion between Global override & Default Styles. (Fix #15640)

  • 1 month later...
Posted

Link: Download Notepad++ v8.7.4 | Notepad++

 

Notepad++ v8.7.4 fix regression & bug-fixes:

 

  1. Fix regression of multi-line tabbar height not updated after closing tabs. (Fix #15905)
  2. Fix the extension defined by user not override language default extensions. (Fix #8035, #8304, #10609, #15826)
  3. Fix encoding of nfo file cannot be changed bug. (Fix #8823, #9153, #13905)

Notepad++ v8.7.3 fix regressions & new enhancements:

 

  1. Fix a crash while disabling “Pin tab” feature. (Fix #15860)
  2. Fix drag&drop a folder in Notepad++ launch redundant dialog regression. (Fix #15869)
  3. Fix docked panels invisibility in multi-instance mode. (Fix #15873)
  4. Add “Pin/Unpin Tab” context menu item. (Fix #15852)
  5. Add “Close All BUT Pinned” command. (Fix #15863)
  6. Fix a possible buffer overflow issue. (Fix #15850)

Notepad++ v8.7.2 new features & bug-fixes:

 

  1. Add Pin tab feature. (Fix #5786, #8377, #12806, #14216)
  2. Tabbar enhancement: Hide inactive tab Close & Pin buttons. (Fix #15298)
  3. Tabbar enhancement: Highlight inactive darken tab on mouse hover. (Fix #15791)
  4. Fix Ctrl-C not doing copy from Search result issue. (Fix #15739)
  5. Add “Minimize / Close to” option for System tray. (Fix #15771)
  6. Add ability to open/copy selected files from Search-results. (Fix #15741)
  7. Fix replace field focus losing when Notepad++ is switched back. (Fix #6021)

  • 3 weeks later...
Posted

Link: Download Notepad++ v8.7.5 | Notepad++

 

Notepad++ v8.7.5 regression-fixes, bug-fixes & enhancements:

 

  1. Fix nfo file losing modification issue (regression from v8.7.4). (Fix #15964)
  2. Fix network file wrong modification detection (regression from v8.7.1). (Fix #15819)
  3. Fix regression “Open Selected PathName(s)” command not working while all selected. (Fix #15960)
  4. Fix unusuability after deleting files in split view. (Fix #15922)
  5. Fix unsaved documents lost on next launch if portable Notepad++ change path. (Fix #1587, #15886)
  6. Refactoring for the better performance & smaller binary size. (Fix #15898)
  7. Improve “Copy Selected Lines” command. (Fix #15803)
  8. Add Visual Basic function list. (Fix #3239)
  9. Add Swift, TypeScript, and Go for advanced Auto-indent. (Fix #15900)
  10. Fix UDL comment line not working due to conflict with stream comment definition. (Fix #11897)
  11. Enhance “Follow current doc.” GUI action/option in Find in files. (Fix #15908)
  12. Fix Reload Workspace not working. (Fix #11551)
  13. Add “Show details” functionality in installer. (Fix #15718)

  • 10 months later...
Posted

Link: Download Notepad++ v8.8.8 | Notepad++

 

Quote

Notepad++ v8.8.8 new features, regression fixes & bug-fixes:

  1. Add Notepad++ MSI (x64) for enterprise IT deployment. (Fix #2326, #2368, #16767)
  2. Security enhancement: prevent Notepad++ Updater from being hijacked. (Implement #17116, commit)
  3. Fix multi-selection crash (regression) when smart highlighting is enabled. (Fix #17086, #17126)
  4. Add tab label length limitation option to have reasonable tab width. (Fix #3332, #5563, #12563, #16417)
  5. Improve the performance of saving session on exit. (Implement #17079)
  6. Fix Distraction free mode disabling tab bar hiding regression. (Fix #17102, #16831)
  7. Add text scale support. (Fix #16427, #17167, #17129)
  8. Fix switching among some encoding not working issue. (Fix #17033)
  9. Fix Notepad++ not handle system default code page UTF-8 well. (Fix #17057)
  10. Improve Rust handling: keywords and autoCompletion. (Fix #16904)

 

  • 3 weeks later...
  • 1 month later...
  • 2 weeks later...
Posted (edited)

Link: Notepad++ Hijacked by State-Sponsored Hackers

 

Quote

2026-02-02

Following the security disclosure published in the v8.8.9 announcement (https://notepad-plus-plus.org/news/v889-released/) the investigation has continued in collaboration with external experts and with the full involvement of my (now former) shared hosting provider.

 

According to the analysis provided by the security experts, the attack involved infrastructure-level compromise that allowed malicious actors to intercept and redirect update traffic destined for notepad-plus-plus.org. The exact technical mechanism remains under investigation, though the compromise occurred at the hosting provider level rather than through vulnerabilities in Notepad++ code itself. Traffic from certain targeted users was selectively redirected to attacker-controlled served malicious update manifests.

 

The incident began from June 2025. Multiple independent security researchers have assessed that the threat actor is likely a Chinese state-sponsored group, which would explain the highly selective targeting observed during the campaign.

 

An incident-response (IR) plan was proposed by the security expert, and I facilitated direct communication between the hosting provider and the IR team. After the IR team engaged with the provider and reviewed the situation, I received the following detailed statement from the provider:

 

Quote

Dear Customer,
We want to further update you following the previous communication with us about your server compromise and further investigation with your incident response team.
We discovered the suspicious events in our logs, which indicate that the server (where your application https://notepad-plus-plus.org/update/getDownloadUrl.php was hosted until the 1st of December, 2025) could have been compromised.
As a precautionary measure, we immediately transferred all clients’ web hosting subscriptions from this server to a new server and continued our further investigation.
Here are the key finding points:
1. The shared hosting server in question was compromised until the 2nd of September, 2025. On this particular date, the server had scheduled maintenance where the kernel and firmware were updated. After this date, we could not identify any similar patterns in logs, and this indicates that bad actors have lost access to the server. We also find no evidence of similar patterns on any other shared hosting servers.
2. Even though the bad actors have lost access to the server from the 2nd of September, 2025, they maintained the credentials of our internal services existing on that server until the 2nd of December, which could have allowed the malicious actors to redirect some of the traffic going to https://notepad-plus-plus.org/getDownloadUrl.php to their own servers and return the updates download URL with compromised updates.
3. Based on our logs, we see no other clients hosted on this particular server being targeted. The bad actors specifically searched for https://notepad-plus-plus.org/ domain with the goal to intercept the traffic to your website, as they might know the then-existing Notepad++ vulnerabilities related to insufficient update verification controls.
4. After concluding our research, the investigated security findings were no longer observed in the web hosting systems from the 2nd of December, 2025, and onwards, as:
* We have fixed vulnerabilities, which could have been used to target Notepad++. In particular, we do have logs indicating that the bad actor tried to re-exploit one of the fixed vulnerabilities; however, the attempt did not succeed after the fix was implemented.
* We have rotated all the credentials that bad actors could have obtained until the 2nd of September, 2025.
* We have checked the logs for similar patterns in all web hosting servers and couldn’t find any evidence of systems being compromised, exploited in a similar way, or data breached.
While we have rotated all the secrets on our end, below you will find the preventive actions you should take to maximize your security. However, if below actions have been done after the 2nd of December, 2025, no actions are needed from your side.
* Change credentials for SSH, FTP/SFTP, and MySQL database.
* Review administrator accounts for your WordPress sites (if you have any), change their passwords, and remove unnecessary users.
* Update your WordPress sites (if you have any) plugins, themes, and core version, and turn on automatic updates, if applicable.
We appreciate your cooperation and understanding. Please let us know in case you have any questions.

 

TL;DR
According to the former hosting provider, the shared hosting server was compromised until 2 September 2025. Even after losing server access, attackers maintained credentials to internal services until 2 December 2025, which allowed them to continue redirecting Notepad++ update traffic to malicious servers. The attackers specifically targeted Notepad++ domain with the goal of exploiting insufficient update verification controls that existed in older versions of Notepad++. All remediation and security hardening were completed by the provider by 2 December 2025, successfully blocking further attacker activity.

 

Note on timelines: The security expert’s analysis indicates the attack ceased on 10 November 2025, while the hosting provider’s statement shows potential attacker access until 2 December 2025. Based on both assessment, I estimate the overall compromise period spanned from June through 2 December 2025, when all attacker access was definitively terminated.

 

I deeply apologize to all users affected by this hijacking. To address this this severe security issue, the Notepad++ website has been migrated to a new hosting provider with significantly stronger security practices. Within Notepad++ itself, WinGup (the updater) was enhanced in v8.8.9 to verify both the certificate and the signature of the downloaded installer. Additionally, the XML returned by the update server is now signed (XMLDSig), and the certificate & signature verification will be enforced starting with upcoming v8.9.2, expected in about one month.

 

With these changes and reinforcements, I believe the situation has been fully resolved. Fingers crossed.

 

 

 

Edited by Arthur
  • Like 1
Posted
On 02/02/2026 at 07:51, kennysarmy said:

Notepad++ v8.9.1 regression fixes, bug-fixes & new improvements:

Doesn't necessarily help if the previous versions were pwned, you don't know what backdoors are already installed. 

Posted (edited)

Link: The Notepad++ supply chain attack — unnoticed execution chains and new IoCs

 

Quote

Multiple execution chains and payloads

Having checked our telemetry related to this incident, we have been amazed to find out how different and unique were the execution chains used in this supply chain attack. We identified that over the course of four months, from July to October 2025, attackers who have compromised Notepad++ have been constantly rotating C2 server addresses used for distributing malicious updates, the downloaders used for implant delivery, as well as the final payloads.

 

We observed three different infection chains overall designed to attack about a dozen machines, belonging to:

 

  •  Individuals located in Vietnam, El Salvador and Australia;
  •  A government organization located in the Philippines;
  •  A financial organization located in El Salvador;
  •  An IT service provider organization located in Vietnam.

 

Despite the variety of payloads observed, Kaspersky solutions have been able to block the identified attacks as they occurred.

 

In this article, we describe the variety of the infection chains we observed in the Notepad++ supply chain attack, as well as provide numerous previously unpublished IoCs related to it. 

 

Edited by Arthur
Posted

I use notepad ++ a lot, work and home 😟. So I guess I should do full virus scans and update to Notepad++ v8.9.1 ?

Has anybody looked though the technical analysis articles to figure out implications if you have been compromised ?

Hopefully someone will come up with a script you can run to check for IoCs 

Posted
1 minute ago, mrstrong said:

I use notepad ++ a lot, work and home 😟. So I guess I should do full virus scans and update to Notepad++ v8.9.1 ?

Has anybody looked though the technical analysis articles to figure out implications if you have been compromised ?

Hopefully someone will come up with a script you can run to check for IoCs 

I may be wrong but from my understanding a lot of the attack were targeting specific end users (likely governments or big corps) so generally speaking most average end users were fine. Best course of action is install the latest version from here: Downloads | Notepad++ v8.9.1 or above if released, you can run a virus scan to be safe across your whole system as well, it would never hurt.

 

Low Level has done a short but information packed video on it, definitely worth a watch if you want more info:

 

 

  • Thanks 1
Posted

Yes, the actual code and application were not compromised, their hosting was. Seems to be a nation state attack, redirecting very specific, targeted users.

  • Like 1
  • 4 weeks later...
Posted

Link: Notepad++ v8.9.2 release - Double‑Lock Update Security | Notepad++

 

Quote

“the XML returned by the update server is now signed (XMLDSig), and the certificate & signature verification will be enforced starting with upcoming v8.9.2, expected in about one month.“


As promised in the announcement Notepad++ Hijacked by State-Sponsored Hackers, this release strengthens the weakest links in Notepad++ update process...

 

Quote

Notepad++ v8.9.2 new security enhancements, feature, regression fix & bug-fix:

  1. Security enhancement: Make updater check integrity & authenticity of server-returned XML (XMLDsig). (Implement #17441)
  2. Security enhancement: Fix untrusted search path vulnerability by launching explorer.exe (Fix CVE-2026-25926)
  3. Security enhancement: Make auto-updater (WinGUp) even more secured. (Remove unsecured options, remove dll dependency, launch only signed program for plugin management)
  4. Fix a plugin installation crash due to incorrect processing catch. (Fix #issue)
  5. Add redact selection feature - Default: █, Modifier (Shift + Click): ●. (Fix #17363)
  6. Fix context menu shortcut localization not aligning to the right regression. (Fix #17467)

 

  • Like 1
  • 4 weeks later...
  • 2 months later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...