The Spy in Your Code Editor: How Beijing Weaponized Developer Trust

· 10 min read · cybersecurity

Every day, millions of software developers, system administrators, and IT professionals open Notepad++. The free text editor has been around for more than two decades, a fixture of Windows desktops since before the iPhone existed. Simple. Reliable. The kind of tool you install once and forget about, like a stapler or a kitchen timer.

For six months last year, some of those developers had company they didn’t know about.

Between June and December 2025, a Chinese state-sponsored hacking group called Lotus Blossom compromised Notepad++‘s update infrastructure and used it to deliver surveillance malware to carefully selected targets. Security researchers at Rapid7 uncovered the campaign and traced it to an espionage group that’s been active since 2009. On February 2, 2026, Notepad++ developer Don Ho published the full disclosure.

This wasn’t a random malware campaign. It was precision intelligence work. And it exposes something uncomfortable about the tools we trust most: trust itself has become a target.


The Attack

The timeline tells a story of patience and precision. Attackers first compromised a shared hosting server used by Notepad++ sometime before June 2025. “The attack involved [an] infrastructure-level compromise that allowed malicious actors to intercept and redirect update traffic destined for notepad-plus-plus.org,” Don Ho explained in his disclosure. The hackers didn’t exploit a bug in Notepad++ itself. They went after the infrastructure that delivered it.

Once inside, they didn’t carpet-bomb every user with malware. They selectively redirected update requests from specific targets to attacker-controlled servers hosting a poisoned version of the software. According to Ho, server access ended on September 2, 2025, but the attackers maintained credentials to internal services until December 2. Six months of access to redirect update traffic at will.

The payload was sophisticated. Rapid7 researchers dubbed the previously undocumented backdoor “Chrysalis” and found it packed with capabilities: reverse shell access, remote command execution, file operations, and persistence mechanisms. Christiaan Beek, Rapid7’s Senior Director of Threat Intelligence, noted that the malware used custom encryption, API hashing, and even Microsoft’s Warbird code protection framework to evade detection. “The discovery of the Chrysalis backdoor,” the Rapid7 report states, “highlights an evolution in Billbug’s capabilities… a clear shift toward more resilient and stealth tradecraft.”

Rapid7 attributed the operation to Lotus Blossom, also known as Billbug and Raspberry Typhoon, with what they termed “moderate confidence.” The group has a long history of targeting government, telecommunications, aviation, critical infrastructure, and media organizations, primarily in Southeast Asia.

Here’s what makes this attack different from a routine breach: the targeting was exquisitely selective. Rather than infecting everyone who updated Notepad++, the attackers cherry-picked victims. Per Beek’s analysis, the targeting focused on “telecommunications and financial services organisations in East Asia.” The tooling, he noted, “is consistent with post-compromise reconnaissance, command execution, and selective data access, rather than broad data harvesting.”

The attackers had access to millions of potential victims. They chose a handful. That’s not opportunistic hacking. That’s intelligence collection.

“I deeply apologise to all users affected by this hijacking,” Don Ho wrote. A single developer maintaining a tool used by millions, blindsided by state-level attackers who exploited his hosting provider rather than his code.


The Pattern

The Notepad++ operation would be alarming enough in isolation. It isn’t isolated.

Over the past two years, Chinese-linked hacking groups have systematically targeted the software supply chain, with particular focus on tools used by developers and IT professionals. Microsoft researchers documented how Silk Typhoon has been targeting IT supply chain organizations, including remote management tools, cloud applications, and identity management platforms. “This approach allows the threat actor to exploit trusted relationships within the IT ecosystem,” Microsoft noted.

The scale is staggering. Salt Typhoon, another Chinese state-sponsored group, infiltrated telecommunications companies in what CISA called one of the most significant cyber espionage campaigns in years. The FBI announced in August 2025 that Salt Typhoon had compromised at least 200 companies across 80 countries. In January 2025, Treasury sanctioned Sichuan Juxinhe Network Technology for direct involvement. In April, the FBI posted a $10 million bounty for information on the actors.

Then there’s Volt Typhoon, which U.S. authorities say has been pre-positioning itself in American critical infrastructure. CISA’s February 2024 advisory warned that Volt Typhoon actors had maintained access to some victim IT environments for at least five years. The purpose isn’t espionage in the traditional sense. It’s preparation for potential disruption during a future crisis.

This isn’t random. It’s a playbook.

We’ve seen it before. In 2024, security researchers narrowly prevented what could have been one of the most devastating supply chain attacks in history. An attacker using the name “Jia Tan” spent three years ingratiating themselves into the XZ Utils project, a widely used compression library. They submitted helpful patches. They did maintenance work. They gained the trust of the project’s burned-out sole maintainer. Then they introduced a backdoor that would have compromised the vast majority of Linux SSH servers on the internet.

The XZ Utils attack was caught by accident when a Microsoft engineer noticed a performance problem and traced it back to the malicious code. The attack received a CVSS severity score of 10.0, the maximum possible.

An analysis in Communications of the ACM put it bluntly: “A competent software engineer working full-time on an open source project for two years to gain the trust of its maintainer probably costs less than a million dollars. A hidden backdoor into the vast majority of Linux ssh servers on the Internet would be worth many times more than that, possibly billions of dollars.”

The math makes sense to intelligence agencies, and targets aren’t hard to find. Sonatype’s 2026 report found that malicious packages in open source repositories have surpassed 1.2 million, with nation-state attackers “increasingly mimicking trusted developer tools.”


The Strategy

Why developer tools? Why not target end users directly, or go after corporate networks through phishing campaigns like everyone else?

Because developer tools provide access to the people who build everything else.

Engineers maintaining government systems use text editors. Telecom network administrators use code repositories. Financial services developers use package managers. Compromise the tools they rely on, and you’ve potentially compromised them, their employers, and the systems they build.

This is strategic thinking, and it has a name: military-civil fusion. CSIS analysis describes how China’s system “draws private firms, academic institutions, and other non-state actors into state cyber operations.” The legal framework makes cooperation mandatory. China’s National Intelligence Law (2017), along with related statutes, requires companies to assist state intelligence operations. “Chinese law mandates the full cooperation of Chinese companies with any request from an intelligence agency,” the CSIS report notes, “and there are no grounds for appeal.”

This creates a unique capability. China can mobilize commercial-grade software development resources for state intelligence purposes, producing malware that’s not just sophisticated but professionally engineered.

The Open Source Security Foundation’s 2025 predictions identified state actors as “one of the biggest threats” to open source software. “Open source software offers them a low-cost, high-reward target for espionage, sabotage, and disruption.”

What makes open source particularly vulnerable is the same thing that makes it valuable: trust. As Red Hat observed, “You don’t necessarily have to know by name the other person who created the code, but you need to trust them.” That trust enables collaboration across borders, companies, and competitors. It’s how strangers can build Linux together.

It’s also an attack surface. Chinese intelligence has figured out how to exploit it.


The Politics

None of this happens in a vacuum.

The FBI has stated plainly that “the counterintelligence and economic espionage efforts emanating from the government of China and the Chinese Communist Party are a grave threat to the economic well-being and democratic values of the United States.”

The Council on Foreign Relations frames the challenge in strategic terms: “Cyber operations serve Beijing’s core national interests. Cyber-enabled espionage advances technological self-sufficiency by acquiring intellectual property. Surveillance and influence campaigns support political control at home and abroad.” More ominously: “China is pre-positioning for crisis and conflict, establishing persistent access to critical infrastructure and military networks that could constrain U.S. decision-making in a future confrontation.”

CFR’s analysts are skeptical that U.S. policy can change Chinese behavior: “Beijing will not abandon these activities because the stakes are too high. They are integral to China’s vision of national rejuvenation and its strategy for competing with the United States.”

That said, complexity matters here. Cyber espionage is not a uniquely Chinese activity. Reporting on the Salt Typhoon campaign noted that the operation, while alarming in scale, was “similar to cyberespionage that the US itself conducts.” Every major power engages in signals intelligence. The United States has its own extensive capabilities.

What distinguishes the pattern we’re seeing isn’t espionage itself but how it’s being conducted: the systematic targeting of trusted infrastructure, the exploitation of open source maintainer vulnerabilities, the patience of multi-year operations designed to gain trust before betraying it. These aren’t just hacks. They’re strategic investments in compromising the foundations of digital trust.

The political response has been mixed. The Trump administration is developing a new cybersecurity strategy that emphasizes offensive operations and “hitting back” at adversaries. Treasury has imposed sanctions. The FBI has posted bounties. Attribution remains challenging, consequences limited.


The Reckoning

For Notepad++, the immediate response was straightforward. Don Ho migrated to a new hosting provider with hardened security. Version 8.8.9, released December 9, 2025, introduced mandatory certificate and signature verification for updates. Beek confirmed that Lotus Blossom’s “unauthorized access appears to have been disrupted.”

One project, one fix. The systemic problem remains.

The Notepad++ model, a beloved tool maintained by a single dedicated developer and used by millions worldwide, is the model for thousands of open source projects. The person behind your text editor, your compression library, your build tool might be one burned-out volunteer away from either abandonment or compromise. XZ Utils showed the pattern. Notepad++ confirmed it.

Trust is what’s being exploited here, and you can’t patch trust with software updates.

For organizations, the lesson is that developer tools are part of your attack surface. The software your engineers use to build your products can be compromised. Supply chain security isn’t just about your vendors. It’s about the tools your people download.

For the open source ecosystem, the lesson is that maintainers need support. Volunteer labor built much of the internet, but volunteer labor is also its soft underbelly. Funding, infrastructure support, and security resources for critical projects aren’t charity. They’re defense spending.

For policymakers, the lesson is that software supply chains are critical infrastructure. They’re not glamorous. They don’t fit neatly into existing regulatory frameworks. But they’re how sophisticated adversaries gain access to the systems we depend on.


The Notepad++ episode will fade from the news. Don Ho patched the vulnerability. Users updated. The hosting provider was changed. Life moves on.

But the episode reveals something that won’t fade. Every time a developer clicks “update,” every time an engineer installs a package, every time a system administrator trusts that the software they’re downloading is what it claims to be, they’re making a trust decision. Chinese intelligence has noticed. They’ve invested years and significant resources into exploiting it.

The question is whether we’ve noticed too.

G.

All views expressed here are my own and do not represent the opinions or positions of my employer or any organization I am affiliated with.

AIL: 0 1 2 3 4 5

Giulio wrote the core content and analysis. claude-opus-4.6 / Anthropic (primary contributor) and other AI models supported with research, sounding board, refinement, and structural editing.