JDownloader Website Hack Exposes Windows and Linux Users to Malicious Installers
ID: bc70107d-aef9-526b-a409-79a233e511ad
STIX ID: report--bc70107d-aef9-526b-a409-79a233e511ad
Feed Name: GBHackers
Threat Score
**Executive summary:** Between May 6–7, 2026, attackers compromised the JDownloader website via an unpatched CMS ACL vulnerability and replaced official Windows and Linux installers with trojanized versions containing a Python-based remote access trojan (RAT), exposing users who downloaded installers during that window to persistent remote access; developers confirmed the breach, took the site offline, restored clean downloads, and performed hardening and patching.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
