JDownloader Website Compromised to Distribute Malicious Windows and Linux Installers
ID: 6bccb8ef-4641-52c0-8454-86ee24199d82
STIX ID: report--6bccb8ef-4641-52c0-8454-86ee24199d82
Feed Name: cybersecurityNews.com
Threat Score
Between May 6–7, 2026 attackers exploited an unpatched CMS vulnerability on the official JDownloader website to replace Windows (alternative) and Linux installers with trojanized versions containing a Python-based Remote Access Trojan (RAT); the site was taken offline, cleaned and patched, users who downloaded installers during the window were advised to verify hashes, re-download, and scan systems, and developers confirmed internal updater users were not affected.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
