Kaspersky Researchers Document New Infection Chains and IoCs in Notepad++ Supply Chain Attack
By
natebc
Hand-rolled, kettle-boiled, baked to perfection. Worth every minute at the bakery.
Summary
Kaspersky GReAT experts discovered previously undocumented infection chains used in the Notepad++ supply chain attack that occurred from June to December 2025. The attack compromised Notepad++'s update infrastructure through a hosting provider incident, allowing attackers to deliver malicious payloads via DLL sideloading and Cobalt Strike Beacon. The article provides new Indicators of Compromise (IoCs) and details multiple execution chains used in the attack, with recommendations for using detection rules in SIEM systems.
Key quotes
· 4 pulledOn February 2, 2026, the developers of Notepad++, a text editor popular among developers, published a statement claiming that the update infrastructure of Notepad++ had been compromised.
According to the statement, this was due to a hosting provider-level incident, which occurred from June to September 2025. However, attackers had been able to retain access to internal services until December 2025.
Kaspersky GReAT experts discovered previously undocumented infection chains used in the Notepad++ supply chain attacks.
The article provides new IoCs related to those incidents which employ DLL sideloading and Cobalt Strike Beacon delivery.
You might also wanna read
Microsoft uncovers supply chain attack: Compromised @antv npm packages steal CI/CD credentials via Mini Shai-Hulud malware
Microsoft has identified an active supply chain attack targeting the @antv npm package ecosystem. A threat actor compromised an @antv mainta
SymJack Attack Exploits AI Coding Agents for Supply Chain Compromise
This article describes a novel supply chain attack called 'SymJack' that targets AI coding agents. The attack exploits the trust and automat
Microsoft uncovers npm supply chain attack stealing cloud and CI/CD credentials via typosquatted packages
Microsoft identified an active supply chain attack (Mini Shai-Hulud campaign) targeting the npm package ecosystem. On May 28, 2026, a threat
FortiGuard Labs Analysis: PureLogs Infostealer Delivered via PawsRunner Steganography Campaign
FortiGuard Labs analyzes a malware campaign using steganography to deliver the PureLogs infostealer. The attack begins with a phishing email
CISA warns security teams of wave of attacks targeting software supply chain credentials
CISA has issued a warning urging security teams to check for software development compromises, specifically regarding a wave of attacks targ

September 2025 NPM supply-chain attack compromises popular JavaScript packages
In September 2025, a coordinated software supply-chain attack targeted multiple popular NPM packages in the JavaScript ecosystem. The attack
