logo

Attackers replaced JDownloader installer downloads with malware

ID: d211bdd0-24b9-54ca-9887-a34fd2ed5e5f

STIX ID: report--d211bdd0-24b9-54ca-9887-a34fd2ed5e5f

Feed Name: Malwarebytes Blog

Threat Score
75/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

...
...

JDownloader's official website was compromised on May 6–7, 2026: attackers altered specific installer downloads (Windows alternative installer and Linux shell installer) to distribute a Python‑based RAT via an unpatched CMS ACL vulnerability. The developers confirmed the breach, removed the site for remediation, restored verified installers by May 8–9, and advised users to check digital signatures and scan systems; Malwarebytes has blocked domains associated with the RAT.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.