Notepad++ addressed a flaw in its updater that allowed attackers to hijack update traffic due to improper authentication of update files in earlier versions.
Beaumont explained that
although downloads are signed, older Notepad++ versions used a self-signed root certificate publicly available on GitHub, weakening validation. Because traffic to notepad-plus-plus.org is rare, ISP-level redirection is feasible for well-resourced actors.
Notepad++ addressed an updater vulnerability that allows attackers hijack update traffic due to weak file authentication.
securityaffairs.com