logo

Official JDownloader site served malware to Windows and Linux users between May 6 and May 7

ID: 7227105b-c500-5426-ad27-bb09f8df3f0e

STIX ID: report--7227105b-c500-5426-ad27-bb09f8df3f0e

Feed Name: Security Affairs

Threat Score
82/100

Date Published: 2026-05-10

Date Updated: 2026-05-11

Author: Pierluigi Paganini

...
...

JDownloader's official site was briefly compromised (May 6–7, 2026), with attackers altering certain download links to deliver malicious Windows and Linux installers containing a Python RAT; affected links were limited to the Windows "Alternative Installer" and the Linux shell installer, developers took the site offline to remediate, and multiple IOCs (file hashes and malicious URLs) were published.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.