
securelist.com
February 3, 2026
13 min read
65/100
Summary
On February 2, 2026, Notepad++ developers reported a compromise of their update infrastructure due to a hosting provider incident between June and September 2025. Attackers maintained access to internal services until December 2025, leading to multiple execution chains and payloads.
Key Takeaways
Community Sentiment
Concerns

Keyv and friends compromised in active Shai-Hulud supply chain attack
Aug 4, 2026

Shai-Hulud Themed Malware Found in the PyTorch Lightning AI Training Library
Apr 30, 2026

Config Files That Run Code: Supply Chain Security Blindspot
Jun 8, 2026

Axios compromised on NPM – Malicious versions drop remote access trojan
Mar 31, 2026

A GitHub Issue Title Compromised 4k Developer Machines
Mar 5, 2026