Attackers replaced JDownloader installer downloads with malware
ID: d211bdd0-24b9-54ca-9887-a34fd2ed5e5f
STIX ID: report--d211bdd0-24b9-54ca-9887-a34fd2ed5e5f
Feed Name: Malwarebytes Blog
Threat Score
JDownloader's official website was compromised on May 6–7, 2026: attackers altered specific installer downloads (Windows alternative installer and Linux shell installer) to distribute a Python‑based RAT via an unpatched CMS ACL vulnerability. The developers confirmed the breach, removed the site for remediation, restored verified installers by May 8–9, and advised users to check digital signatures and scan systems; Malwarebytes has blocked domains associated with the RAT.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
