Trust Hijacked: Official JDownloader Website Breached to Distribute Malicious Installers
ID: 36100678-7718-5340-83d0-dde6dd5d0389
STIX ID: report--36100678-7718-5340-83d0-dde6dd5d0389
Feed Name: securityonline.info
**JDownloader website compromise:** Attackers exploited an unpatched backend vulnerability to modify ACLs and replace alternative Windows and Linux installers on the official JDownloader download page between May 6–7, delivering malicious installers to users; macOS installers, the core JDownloader.jar, package manager distributions (Flatpak, Winget, Snap), and in-app auto-updates were reported unaffected, but users who downloaded the affected installers are advised to treat their machines as compromised.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
