Notepad++ Fixes Hijacked Update Mechanism Used to Deliver Targeted Malware
The Hacker News | #1 Trusted Source for Cybersecurity News [Uno…
February 18, 2026
Notepad++ has released a security fix to plug gaps that were exploited by an advanced threat actor from China to hijack the software update mechanism to selectively deliver malware to targets of interest.
The version 8.9.2 update incorporates what maintainer Don Ho calls a "double lock" design that aims to make the update process "robust and effectively unexploitable." This includes verification
Discussion in the ATmosphere