In February 2026, developers disclosed that Notepad++ update infrastructure was compromised from June to September 2025, with attackers maintaining access until December 2025. Kaspersky identified three distinct infection chains targeting machines in Vietnam, El Salvador, Australia, and the Philippines, affecting individuals, government organizations, financial institutions, and IT service providers through malicious updates that deployed various payloads including Cobalt Strike Beacon.