2026 Notepad++ — Supply chain attack via update infrastructure
Data compromised
Malware delivery vector
Technical writeup
Critical supply chain attack Feb 2, 2026. Update infrastructure compromised through hosting provider-level incident. Attackers abused update mechanism to deliver targeted malware.
Root cause
Supply chain; hosting provider compromise